
GIAC Security Operations Certified
Domain 2Objective 4
Interpreting Events GSOC Practice Questions (Page 3)
Part of the Network and Event Analysis domain, which makes up ~38% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~19–30 in this domain), expect 5–8 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)
45questions here
9free pages
7concepts
Questions 11–15
- 11
A SOC receives three alerts: (1) a low-severity IDS alert for a port scan from an external IP, (2) a medium-severity alert for a malware signature on a user's workstation, and (3) a high-severity alert for a potential privilege escalation on a domain controller. The analyst has time to investigate only one alert. Which alert should be investigated first?
Select an answer first - 12
A SOC analyst sees two events: a firewall log showing an outbound connection from a finance workstation to a known malware domain, and an IDS alert for a signature matching that domain. The workstation belongs to the CFO, whose account has elevated access to financial systems. Which action best applies event prioritization principles?
Select an answer first - 13
A SOC analyst is reviewing an alert that shows a user account downloading a large file from an internal file server. The user is a junior accountant. The analyst must decide whether this is a security incident. Which additional context would be most valuable in making this decision?
Select an answer first - 14
A security analyst is reviewing logs and sees a single failed login attempt from an internal IP to a server. There are no other events. What is the most appropriate interpretation?
Select an answer first - 15
An analyst is investigating a potential data breach. The analyst has the following events: (1) a firewall log showing an outbound connection to a cloud storage service from a server in the HR department, (2) a host log showing a large file compression activity on the same server, and (3) an IDS alert for a known data exfiltration tool signature. The analyst must determine if these events are related. Which approach is most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSOC” is a trademark of its owner, used for identification only.