Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Security Operations Certified

Domain 2Objective 4

Interpreting Events GSOC Practice Questions (Page 1)

Part of the Network and Event Analysis domain, which makes up ~38% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~19–30 in this domain), expect 5–8 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)

45questions here
9free pages
7concepts

Questions 1–5

  1. 1expert · hard

    An analyst is correlating events from multiple sources. A firewall log shows a connection to a known malicious IP. A DNS log shows a query for a domain that resolves to that IP. A host log shows a process named 'svchost.exe' making the query. The host is a critical server. What is the most appropriate next step?

    Select an answer first
  2. 2foundation · easy

    Which scenario best illustrates event correlation?

    Select an answer first
  3. 3expert · hard

    An analyst sees a series of events: a user receives a phishing email, clicks a link, downloads a file, and then the file executes. The antivirus does not detect the file. The user is in the HR department. What is the most appropriate action?

    Select an answer first
  4. 4expert · hard

    After a multi-day incident, an analyst must create a report for management. The report should support both legal review and future detection improvements. What is the best approach?

    Select an answer first
  5. 5foundation · easy

    In network security, what is the primary purpose of event analysis?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSOC” is a trademark of its owner, used for identification only.