Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Security Operations Manager

Domain 1Objective 1

Cyber Defense Theory, Threat Intel, and Defensible Architecture GSOM Practice Questions (Page 4)

Part of the SOC Strategy and Architecture domain, which makes up ~31% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~16–25 in this domain), expect 5–8 from this objective — we provide 56 practice questions to prepare you well beyond it. (estimate)

56questions here
12free pages
12concepts

Questions 16–20

  1. 16expert · hard

    A SOC manager is designing a logging architecture for a large enterprise. The requirement is to detect advanced threats that may use legitimate credentials. The SOC has limited storage and must prioritize which logs to collect. Which approach best balances visibility and storage constraints?

    Select an answer first
  2. 17expert · hard

    A SOC manager is designing a logging and monitoring architecture for a hybrid environment with on-premises servers and cloud workloads. The manager must ensure comprehensive visibility while managing storage costs and meeting a regulatory requirement to retain logs for one year. The team has limited staffing for log management. Which approach best balances these constraints?

    Select an answer first
  3. 18application · medium

    A SOC manager is redesigning the network for a mid-sized financial services firm. The firm's applications are distributed across multiple VLANs, and the security team has observed that once an attacker compromises a single workstation, they are able to move laterally to the database tier within minutes. The manager wants to implement a segmentation strategy that will most directly impede lateral movement while minimizing disruption to existing application flows. Which approach should the manager prioritize?

    Select an answer first
  4. 19expert · hard

    A SOC manager is explaining to the CISO why the SOC needs to implement both preventive and detective controls. The CISO asks why the company cannot rely solely on strong preventive controls. Which response best justifies the need for detective controls?

    Select an answer first
  5. 20application · medium

    A company is moving to a zero trust architecture and wants to ensure that its SOC has the visibility needed to enforce continuous verification. The company has a mix of on-premises servers and cloud applications accessed by employees from various locations. Which combination of controls will best support zero trust principles while providing the SOC with the necessary data?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSOM” is a trademark of its owner, used for identification only.