
GIAC Security Operations Certified
Domain 1Objective 3
SOC Management Systems GSOC Practice Questions (Page 6)
Part of the Security Operations Fundamentals domain, which makes up ~30% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 5–8 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)
49questions here
10free pages
7concepts
Questions 26–30
- 26
A SOC must comply with GDPR when handling personal data of EU citizens. Which practice is most directly required by GDPR?
Select an answer first - 27
What is the primary purpose of the triage step in a SOC incident workflow?
Select an answer first - 28
A SOC has a team of five analysts. During a large-scale incident, the SOC manager assigns one analyst to lead the investigation, one to handle communication with management, one to monitor the SIEM for new alerts, and two to perform containment. The incident requires deep forensic analysis. Which adjustment best improves the team's effectiveness?
Select an answer first - 29
What is the primary function of a Security Orchestration, Automation, and Response (SOAR) platform in a SOC?
Select an answer first - 30
A SOC uses a SIEM, a ticketing system, and a SOAR. The team notices that alerts are not being consistently enriched with threat intelligence before being assigned to analysts. Which integration is most likely missing?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSOC” is a trademark of its owner, used for identification only.