
GIAC Security Operations Certified
Domain 3Objective 2
Analytic Design and Tuning GSOC Practice Questions (Page 9)
Part of the Incident Response and Optimization domain, which makes up ~32% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~16–26 in this domain), expect 5–9 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)
51questions here
11free pages
10concepts
Questions 41–45
- 41
An analytic that detects 'pass-the-hash' activity is producing both false positives and false negatives. The false positives come from a legitimate application that uses the same NTLM hash for multiple logons. The false negatives occur because the analytic only looks at a single event ID, and some attacks use a different event ID. The team must improve the analytic without increasing the alert volume significantly. Which approach is best?
Select an answer first - 42
An analytic that alerts on 'new local admin accounts created on workstations' is generating false positives because IT support uses a script that temporarily creates and deletes local admin accounts during maintenance. The team wants to reduce false positives without missing real persistence. Which tuning action is most effective?
Select an answer first - 43
A SOC has tuned an analytic to reduce false positives, but the change also reduces the alert's severity from 'High' to 'Medium'. The incident response team relies on severity to prioritize alerts. What is the most important action to take?
Select an answer first - 44
A SOC runs a complex analytic that joins firewall logs with Active Directory account data to detect 'impossible travel' logins. The query takes over 10 minutes to run and times out, causing missed detections. The team needs to improve performance without losing detection capability. Which approach is best?
Select an answer first - 45
A security team is developing a use case to detect 'data exfiltration via DNS tunneling'. They have access to DNS query logs, firewall logs, and NetFlow. The team wants to minimize the number of alerts while still detecting the technique. Which analytic approach best fits the use case?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSOC” is a trademark of its owner, used for identification only.