
GIAC Security Operations Manager
Domain 1Objective 1
Cyber Defense Theory, Threat Intel, and Defensible Architecture GSOM Practice Questions (Page 7)
Part of the SOC Strategy and Architecture domain, which makes up ~31% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~16–25 in this domain), expect 5–8 from this objective — we provide 56 practice questions to prepare you well beyond it. (estimate)
56questions here
12free pages
12concepts
Questions 31–35
- 31
A SOC manager is establishing a threat intelligence program. The first step is to define what intelligence the SOC needs to support its detection and response priorities. Which stage of the threat intelligence lifecycle does this represent?
Select an answer first - 32
How can threat intelligence be integrated into SOC workflows to enhance detection?
Select an answer first - 33
A SOC manager is designing a new secure environment for a high-value application. The requirement is to minimize the attack surface and limit the impact of a potential compromise. Which design principle is most important to apply?
Select an answer first - 34
Which component is essential for a logging and monitoring architecture to support effective threat detection?
Select an answer first - 35
A SOC manager wants to integrate threat intelligence into the SOC workflow. The SOC receives a commercial feed of IOCs and a separate feed of TTPs. The team is overwhelmed by the volume of IOC alerts. Which approach best uses both feeds to improve detection and reduce alert fatigue?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSOM” is a trademark of its owner, used for identification only.