
GIAC Security Operations Certified
Domain 3Objective 2
Analytic Design and Tuning GSOC Practice Questions (Page 2)
Part of the Incident Response and Optimization domain, which makes up ~32% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~16–26 in this domain), expect 5–9 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)
51questions here
11free pages
10concepts
Questions 6–10
- 6
Which of the following is a key input to the continuous improvement process for security analytics?
Select an answer first - 7
Which of the following best describes the principle of 'scope' in analytic design?
Select an answer first - 8
A SOC's analytic for 'malware C2 beaconing' alerts when a host makes a connection to an external IP every 60 seconds. The analytic has a high false positive rate because some legitimate software also polls at regular intervals. The team wants to reduce false positives while still detecting beaconing. Which approach is most effective?
Select an answer first - 9
What is the primary risk of over-tuning an analytic to eliminate false positives?
Select an answer first - 10
A SOC has a quarterly review process for all analytics. During a review, they find that an analytic for 'privilege escalation' has not triggered in six months, but a recent penetration test showed that the technique it detects is still possible. What should the team do?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSOC” is a trademark of its owner, used for identification only.