
GIAC Security Operations Manager
Domain 1Objective 1
Cyber Defense Theory, Threat Intel, and Defensible Architecture GSOM Practice Questions (Page 10)
Part of the SOC Strategy and Architecture domain, which makes up ~31% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~16–25 in this domain), expect 5–8 from this objective — we provide 56 practice questions to prepare you well beyond it. (estimate)
56questions here
12free pages
12concepts
Questions 46–50
- 46
A SOC team receives a commercial threat intelligence feed that provides IP addresses and domain names associated with known malware campaigns. The team wants to use this feed to improve detection. Which action best leverages this type of intelligence?
Select an answer first - 47
Which of the following is an example of a key performance indicator (KPI) for a SOC?
Select an answer first - 48
A SOC manager is designing a new secure enclave for a high-value application that processes payment card data. The manager wants to apply defensible architecture principles to minimize the attack surface and contain potential breaches. Which design decision best aligns with these principles?
Select an answer first - 49
A SOC manager is preparing a briefing for the board of directors about the threat landscape. The briefing should focus on the motivations and capabilities of adversaries targeting the financial sector, and the potential business impact. Which type of threat intelligence is most appropriate for this audience?
Select an answer first - 50
What is the key difference between traditional network segmentation and micro-segmentation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSOM” is a trademark of its owner, used for identification only.