
GIAC Security Operations Manager
Domain 1Objective 1
Cyber Defense Theory, Threat Intel, and Defensible Architecture GSOM Practice Questions (Page 3)
Part of the SOC Strategy and Architecture domain, which makes up ~31% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~16–25 in this domain), expect 5–8 from this objective — we provide 56 practice questions to prepare you well beyond it. (estimate)
56questions here
12free pages
12concepts
Questions 11–15
- 11
Why are TTPs generally considered more valuable than IOCs for long-term detection strategy?
Select an answer first - 12
A company is implementing zero trust and the SOC manager must ensure that the SOC can monitor access decisions. The company uses a mix of on-premises and cloud applications. Which approach best supports zero trust monitoring?
Select an answer first - 13
What is the primary security benefit of network segmentation?
Select an answer first - 14
A SOC manager is responsible for a multi-tenant environment where different business units host applications with varying sensitivity levels. The manager wants to implement network segmentation to limit lateral movement, but the business units have conflicting requirements: one unit needs to share data with another unit's application, and a third unit requires low-latency access to a shared database. The manager must balance security with operational needs. Which segmentation strategy is most appropriate?
Select an answer first - 15
What is a key benefit of using threat intelligence to prioritize alerts in a SOC?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSOM” is a trademark of its owner, used for identification only.