
GIAC Security Operations Certified
Domain 1Objective 1
Blue Team Defense Concepts GSOC Practice Questions (Page 6)
Part of the Security Operations Fundamentals domain, which makes up ~30% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 5–8 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)
47questions here
10free pages
7concepts
Questions 26–30
- 26
What is the primary purpose of continuous security monitoring?
Select an answer first - 27
A company experiences a data breach. The incident response team is in the 'lessons learned' phase. The team identifies that the SOC did not have a clear escalation path for alerts that were initially classified as low priority. The team wants to implement a process improvement. What is the most effective action?
Select an answer first - 28
A threat intelligence platform provides the SOC with a report on a new malware family. The report includes a list of IOCs, but the SOC's SIEM does not have any rules for these IOCs. The SOC also has limited resources and must decide how to prioritize the implementation of new detection rules. What is the MOST important factor to consider when prioritizing?
Select an answer first - 29
A security architect is designing a defense-in-depth strategy for a financial services company. The company handles highly sensitive customer data and must protect against both external attackers and insider threats. Which approach BEST exemplifies the principle of layering?
Select an answer first - 30
During an incident, what is the goal of containment?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSOC” is a trademark of its owner, used for identification only.