
GIAC Security Leadership
Domain 3Objective 1
Managing a Security Operations Center GSLC Practice Questions (Page 7)
Part of the Security Operations and Incident Management domain, which makes up ~20% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~14–24 in this domain), expect 4–6 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)
46questions here
10free pages
6concepts
Questions 31–35
- 31
Which SOC role is typically responsible for conducting deep-dive analysis of complex security incidents and recommending containment strategies?
Select an answer first - 32
A SOC receives a high-priority alert for a potential data exfiltration from a database server. The Tier 1 analyst on duty is new and unsure whether the alert is a true positive. The incident response manager is unavailable. According to standard SOC escalation procedures, what should the analyst do?
Select an answer first - 33
Which of the following is a core function of a Security Operations Center?
Select an answer first - 34
During a major incident, a SOC analyst discovers that the incident response playbook is outdated and does not cover the current malware variant. What is the best course of action?
Select an answer first - 35
A SOC analyst is working a shift and receives an alert indicating a possible brute-force attack on a critical server. The analyst has confirmed the alert is a true positive. According to the SOC's procedures, what should the analyst do next?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSLC” is a trademark of its owner, used for identification only.