
GIAC Security Operations Certified
Domain 1Objective 3
SOC Management Systems GSOC Practice Questions (Page 5)
Part of the Security Operations Fundamentals domain, which makes up ~30% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 5–8 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)
49questions here
10free pages
7concepts
Questions 21–25
- 21
A SOC is required to comply with PCI DSS. The compliance officer asks the SOC manager to ensure that incident response activities are properly documented and that evidence is preserved. Which role is primarily responsible for ensuring that evidence is collected and preserved according to legal and compliance requirements?
Select an answer first - 22
A SOC has been operating for two years. It has defined processes, but no formal metrics are tracked, and there is no executive reporting. The SOC manager wants to improve maturity. Which action would most directly advance the SOC to the next maturity level?
Select an answer first - 23
In a typical SOC, which role is primarily responsible for monitoring alerts and performing initial triage?
Select an answer first - 24
Which of the following is a common KPI used to measure SOC effectiveness?
Select an answer first - 25
A SOC handles personal data for customers in the European Union. The SOC manager must ensure that incident response processes comply with GDPR requirements. Which action is most directly required by GDPR in the context of incident response?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSOC” is a trademark of its owner, used for identification only.