Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Security Operations Certified

Domain 2Objective 4

Interpreting Events GSOC Practice Questions (Page 2)

Part of the Network and Event Analysis domain, which makes up ~38% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~19–30 in this domain), expect 5–8 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)

45questions here
9free pages
7concepts

Questions 6–10

  1. 6expert · medium

    A SOC analyst is investigating a potential insider threat. The analyst has the following events: (1) a firewall log showing a user accessing a file-sharing website, (2) a host log showing the user copying files to a USB drive, and (3) an HR report that the user is about to be terminated. The analyst must decide whether to escalate this to incident response. Which action is most appropriate?

    Select an answer first
  2. 7application · medium

    An IDS alerts on outbound traffic from a web server to an IP listed on a threat intelligence feed. The analyst checks the web server logs and finds the traffic was a response to a user request for a legitimate third-party API. What should the analyst do?

    Select an answer first
  3. 8application · medium

    A SOC analyst is triaging three alerts: (1) an IDS alert for a port scan from an external IP, (2) a firewall alert for an outbound connection to a file-sharing site from a low-privilege user's workstation, and (3) a host log showing a failed login to a domain controller. The analyst has limited time and must prioritize which alert to investigate first. Which alert should be treated as the highest priority?

    Select an answer first
  4. 9application · medium

    An analyst sees a firewall log showing a blocked outbound connection to a known command-and-control IP. Separately, a host log shows a process making repeated DNS queries to a domain that resolves to that IP. What does the correlation suggest?

    Select an answer first
  5. 10application · medium

    A SOC analyst is triaging alerts and has limited time. The alerts are: (1) a low-severity IDS alert for a port scan, (2) a medium-severity alert for a malware signature on a user's workstation, and (3) a high-severity alert for a potential data exfiltration from a database server. Which alert should be investigated first?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSOC” is a trademark of its owner, used for identification only.