Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Security Operations Certified

Domain 1Objective 1

Blue Team Defense Concepts GSOC Practice Questions (Page 1)

Part of the Security Operations Fundamentals domain, which makes up ~30% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 5–8 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)

47questions here
10free pages
7concepts

Questions 1–5

  1. 1expert · hard

    A security operations center is implementing a new monitoring strategy. They have a SIEM that collects logs from firewalls, servers, and applications. They are considering adding a new data source: NetFlow from their core routers. The team's goal is to improve their ability to detect data exfiltration. Which statement BEST describes the value of adding NetFlow?

    Select an answer first
  2. 2foundation · easy

    Which of the following best describes the primary objective of a blue team in security operations?

    Select an answer first
  3. 3expert · hard

    A security operations team is reviewing threat intelligence from multiple sources. Source A is a commercial feed that provides IOCs with high confidence but is often delayed by several days. Source B is an open-source feed that provides IOCs in near real-time but has a high false-positive rate. The team has limited resources and cannot process all alerts. Which strategy BEST balances the need for timely detection with the need for accuracy?

    Select an answer first
  4. 4foundation · easy

    In defensive strategy, what is the primary purpose of defense in depth (layering)?

    Select an answer first
  5. 5application · medium

    A security analyst detects a single workstation beaconing to a known C2 domain. The malware is memory-resident and has not persisted to disk. The analyst isolates the host, captures a memory image, and kills the malicious process. According to the incident response lifecycle, which phase is the analyst performing when they terminate the process?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSOC” is a trademark of its owner, used for identification only.