
GIAC Security Operations Manager
Domain 1Objective 1
Cyber Defense Theory, Threat Intel, and Defensible Architecture GSOM Practice Questions (Page 6)
Part of the SOC Strategy and Architecture domain, which makes up ~31% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~16–25 in this domain), expect 5–8 from this objective — we provide 56 practice questions to prepare you well beyond it. (estimate)
56questions here
12free pages
12concepts
Questions 26–30
- 26
A SOC receives logs from multiple sources, but the SIEM is generating a high number of false positives because the same event is logged in different formats with different field names. The SOC manager wants to reduce false positives without losing detection capability. Which action is most effective?
Select an answer first - 27
What is the primary purpose of the 'Feedback' stage in the threat intelligence lifecycle?
Select an answer first - 28
Which type of threat intelligence is most commonly consumed by security operations center (SOC) analysts for day-to-day detection and response?
Select an answer first - 29
What is the purpose of data normalization in a SIEM environment?
Select an answer first - 30
A SOC manager is integrating threat intelligence into the incident response process. The team has access to a commercial IOC feed and an information-sharing community that provides detailed TTP reports. The manager wants to reduce the time to detect and respond to incidents while avoiding alert fatigue. The SOC currently has a high false-positive rate from intelligence-based alerts. Which strategy best addresses this challenge?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSOM” is a trademark of its owner, used for identification only.