Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Security Operations Manager

Domain 3Objective 1

Continuous Improvement GSOM Practice Questions (Page 6)

Part of the Performance and Improvement domain, which makes up ~20% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 5–8 from this objective — we provide 54 practice questions to prepare you well beyond it. (estimate)

54questions here
11free pages
8concepts

Questions 26–30

  1. 26application · medium

    A security operations manager wants to establish a feedback loop to improve incident response playbooks. The team has a monthly operations review, but analysts rarely contribute. Which action would most effectively create a sustainable feedback mechanism?

    Select an answer first
  2. 27application · medium

    A security operations team successfully reduced false positives by updating detection rules, but after two months, the false positive rate is creeping back up. The manager wants to sustain the improvement. Which practice would best reinforce the change?

    Select an answer first
  3. 28expert · hard

    A security operations team implemented a new process to reduce the number of repeat incidents. After three months, the repeat incident rate has not changed. The manager is considering whether to continue the process or abandon it. Which evaluation approach would provide the most reliable basis for this decision?

    Select an answer first
  4. 29application · medium

    A security operations manager wants to foster a culture of continuous improvement within the SOC. The manager has noticed that analysts are hesitant to report near-misses or minor process inefficiencies because they fear being blamed. Which action is most aligned with the principles of continuous improvement?

    Select an answer first
  5. 30application · medium

    A security operations team has been experiencing an increasing number of false-positive alerts from a specific intrusion detection rule. The team has been tuning the rule repeatedly, but the false positives persist. The manager wants to identify the underlying reason before making further changes. Which approach best supports this goal?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSOM” is a trademark of its owner, used for identification only.