Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Security Operations Certified

Domain 1Objective 1

Blue Team Defense Concepts GSOC Practice Questions (Page 3)

Part of the Security Operations Fundamentals domain, which makes up ~30% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 5–8 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)

47questions here
10free pages
7concepts

Questions 11–15

  1. 11application · medium

    During a security incident, the SOC identifies that a compromised account was used to access a database containing customer PII. The SOC needs to inform the database administrator (DBA) to check for unauthorized data exports. Which communication practice is most appropriate?

    Select an answer first
  2. 12expert · hard

    During a major security incident, the incident response team discovers that the attacker has compromised a domain controller and is using it to authenticate to other systems. The team needs to contain the incident, but the domain controller is also critical for authentication across the entire organization. The CIO is hesitant to take the domain controller offline because it will cause a major outage. What is the BEST course of action?

    Select an answer first
  3. 13application · easy

    A company's security team wants to detect and block known exploit attempts at the network perimeter before they reach internal servers. They also want to log all blocked attempts for later analysis. Which technology should they deploy?

    Select an answer first
  4. 14expert · hard

    A SOC is overwhelmed by a high volume of false positives from a new SIEM rule. The rule was designed to detect a specific threat, but it is triggering on normal administrative activity. The team must reduce the noise without losing the ability to detect the threat. What is the most effective approach?

    Select an answer first
  5. 15application · medium

    A security analyst has confirmed a malware infection on a server that hosts a critical customer-facing application. The analyst has isolated the server and is now preparing to contain the incident. Who should the analyst involve in the containment decision to minimize business impact?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSOC” is a trademark of its owner, used for identification only.