Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Security Operations Certified

Domain 3Objective 1

Intrusion Triage and Analysis GSOC Practice Questions (Page 2)

Part of the Incident Response and Optimization domain, which makes up ~32% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~16–26 in this domain), expect 5–9 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)

49questions here
10free pages
8concepts

Questions 6–10

  1. 6application · medium

    After triaging an alert, an analyst determines that a user's machine was infected with ransomware, and the machine has been isolated. The analyst needs to communicate the findings to the management. What is the most important information to include in the communication?

    Select an answer first
  2. 7application · medium

    An analyst sees an alert for a suspicious PowerShell command on a server. The command is obfuscated and the server is internet-facing. What is the best next step?

    Select an answer first
  3. 8application · medium

    A SOC team is overwhelmed by the volume of alerts. They want to implement automation to reduce the workload. Which automation strategy is most effective for improving triage efficiency without sacrificing accuracy?

    Select an answer first
  4. 9application · medium

    A SOC is triaging an alert that a user's workstation made an outbound connection to a suspicious domain. The analyst has access to the firewall logs, the endpoint's process execution logs, and the threat intelligence feed that flagged the domain. Which combination of data sources would most efficiently confirm or refute the alert?

    Select an answer first
  5. 10expert · hard

    An analyst is triaging an alert on a domain controller. The alert indicates a successful logon from a foreign IP address at 3:00 AM using a service account that has never logged on from that IP. The organization's policy requires immediate containment for any suspected compromised privileged account, but the analyst also sees that the account is used by a scheduled backup job that runs from a cloud provider. The backup job's documentation states it uses a different IP range. What should the analyst do first?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSOC” is a trademark of its owner, used for identification only.