Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Security Operations Certified

Domain 2Objective 4

Interpreting Events GSOC Practice Questions (Page 3)

Part of the Network and Event Analysis domain, which makes up ~38% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~19–30 in this domain), expect 5–8 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)

45questions here
9free pages
7concepts

Questions 11–15

  1. 11application · medium

    A SOC receives three alerts: (1) a low-severity IDS alert for a port scan from an external IP, (2) a medium-severity alert for a malware signature on a user's workstation, and (3) a high-severity alert for a potential privilege escalation on a domain controller. The analyst has time to investigate only one alert. Which alert should be investigated first?

    Select an answer first
  2. 12application · medium

    A SOC analyst sees two events: a firewall log showing an outbound connection from a finance workstation to a known malware domain, and an IDS alert for a signature matching that domain. The workstation belongs to the CFO, whose account has elevated access to financial systems. Which action best applies event prioritization principles?

    Select an answer first
  3. 13application · medium

    A SOC analyst is reviewing an alert that shows a user account downloading a large file from an internal file server. The user is a junior accountant. The analyst must decide whether this is a security incident. Which additional context would be most valuable in making this decision?

    Select an answer first
  4. 14application · medium

    A security analyst is reviewing logs and sees a single failed login attempt from an internal IP to a server. There are no other events. What is the most appropriate interpretation?

    Select an answer first
  5. 15application · medium

    An analyst is investigating a potential data breach. The analyst has the following events: (1) a firewall log showing an outbound connection to a cloud storage service from a server in the HR department, (2) a host log showing a large file compression activity on the same server, and (3) an IDS alert for a known data exfiltration tool signature. The analyst must determine if these events are related. Which approach is most effective?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSOC” is a trademark of its owner, used for identification only.