
GIAC Security Operations Certified
Domain 1Objective 2
Endpoint Defense GSOC Practice Questions (Page 2)
Part of the Security Operations Fundamentals domain, which makes up ~30% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 5–8 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)
53questions here
11free pages
7concepts
Questions 6–10
- 6
An analyst needs to detect when a user logs into an endpoint outside of normal business hours. Which log source and condition should be used?
Select an answer first - 7
An EDR alert shows that a process on a server is making outbound connections to a known malicious IP. The process is a legitimate application that is used for remote administration. The analyst suspects the application has been compromised. Which action should the analyst take to confirm the compromise?
Select an answer first - 8
Which capability is a defining feature of Endpoint Detection and Response (EDR) solutions?
Select an answer first - 9
During an incident response, an analyst discovers that an attacker used a valid user's credentials to access a file server and exfiltrate data. The analyst has isolated the affected endpoint and collected memory and disk images. What should the analyst do next to prevent further unauthorized access?
Select an answer first - 10
A company is hardening its Windows endpoints. Which configuration change is the most effective in reducing the attack surface for credential theft?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSOC” is a trademark of its owner, used for identification only.