
GIAC Security Operations Certified
Domain 3Objective 2
Analytic Design and Tuning GSOC Practice Questions (Page 1)
Part of the Incident Response and Optimization domain, which makes up ~32% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~16–26 in this domain), expect 5–9 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)
51questions here
11free pages
10concepts
Questions 1–5
- 1
What is the purpose of validating a security analytic using historical data?
Select an answer first - 2
Which of the following is a key component of a well-written security use case?
Select an answer first - 3
A SOC's analytic for 'lateral movement via SMB' only alerts when a single source IP connects to more than 10 distinct destination IPs on port 445 within 5 minutes. An attacker is moving slowly, connecting to one or two machines at a time, and is not being detected. What tuning change would best reduce this false negative?
Select an answer first - 4
What is the purpose of continuous improvement in the context of security analytics?
Select an answer first - 5
A SOC's analytic for 'malicious PowerShell' only detects encoded commands. A recent incident involved a PowerShell script that was not encoded, and the analytic missed it. The team wants to improve detection of non-encoded malicious PowerShell without generating excessive false positives. Which approach is best?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSOC” is a trademark of its owner, used for identification only.