
GIAC Security Operations Certified
Domain 3Objective 1
Intrusion Triage and Analysis GSOC Practice Questions (Page 6)
Part of the Incident Response and Optimization domain, which makes up ~32% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~16–26 in this domain), expect 5–9 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)
49questions here
10free pages
8concepts
Questions 26–30
- 26
An analyst is triaging an alert that a user's machine is sending large amounts of data to an external IP. The analyst checks the endpoint logs and sees that a backup application is running and is configured to send backups to a cloud storage provider. The external IP belongs to the cloud provider. However, the data volume is significantly higher than normal for this backup job. What is the most appropriate action?
Select an answer first - 27
A SOC analyst is triaging an alert that a user's machine has a file with a hash that matches a known malware sample. The analyst also sees that the file has not been executed and is located in the user's Downloads folder. The user is a known researcher who frequently downloads malware samples for analysis. What is the most appropriate action?
Select an answer first - 28
An analyst is triaging an alert that a user's machine made a connection to an IP address that is on a threat intel feed as a known C2 server. The analyst checks the endpoint logs and sees that the connection was made by a legitimate system process (svchost.exe). The process is running from the correct system path. Which conclusion is most appropriate?
Select an answer first - 29
A SOC analyst is triaging an alert that indicates a user visited a malicious URL. The proxy log shows the URL, but the endpoint logs show no infection. The analyst has access to DNS logs, EDR telemetry, and threat intelligence. Which combination of data sources would best confirm whether the visit resulted in an infection?
Select an answer first - 30
During triage, an analyst sees an alert that a workstation downloaded a file with a SHA256 hash that matches a known malware signature. The analyst also observes that the file was executed and then made a DNS query for a domain that is not yet blocklisted. Which IOC type is most useful for confirming the alert as a true positive?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSOC” is a trademark of its owner, used for identification only.