
GIAC Security Operations Certified
Domain 3Objective 2
Analytic Design and Tuning GSOC Practice Questions (Page 10)
Part of the Incident Response and Optimization domain, which makes up ~32% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~16–26 in this domain), expect 5–9 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)
51questions here
11free pages
10concepts
Questions 46–50
- 46
When selecting a data source for a security analytic, which of the following is the MOST important criterion?
Select an answer first - 47
A SOC team has tuned an analytic to reduce false positives, but after a month, the alert volume has increased again because the IT team adopted a new administrative tool that triggers the same pattern. What is the most effective continuous improvement step?
Select an answer first - 48
Which technique is specifically used to reduce false positives in a security analytic?
Select an answer first - 49
A SOC has an analytic that detects 'pass-the-hash' activity. After a major Windows update, the analytic starts generating many false positives because the update changes how certain authentication events are logged. The SOC needs to address this quickly while maintaining detection capability. What is the best course of action?
Select an answer first - 50
Why is it important to minimize false negatives in security analytics?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSOC” is a trademark of its owner, used for identification only.