
GIAC Security Operations Certified
Domain 1Objective 2
Endpoint Defense GSOC Practice Questions (Page 11)
Part of the Security Operations Fundamentals domain, which makes up ~30% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 5–8 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)
53questions here
11free pages
7concepts
Questions 51–53
- 51
A security analyst is responding to a suspected endpoint compromise. The EDR shows a process running from a user-writable folder, and the process has an invalid digital signature. The analyst must preserve evidence for potential legal action. The endpoint is a critical server that cannot be taken offline for more than a few minutes. Which approach best balances evidence preservation and operational continuity?
Select an answer first - 52
Which action is part of the containment phase of endpoint incident response?
Select an answer first - 53
A security team is designing an endpoint logging strategy. They need to detect lateral movement using remote PowerShell (WinRM) and also detect use of stolen credentials. They have limited storage and must prioritize logs. Which logging configuration is the most effective for these detections?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GSOC
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSOC” is a trademark of its owner, used for identification only.