
GIAC Security Operations Manager
Domain 2Objective 1
Data Source Assessment and Collection GSOM Practice Questions (Page 2)
Part of the Detection and Response Operations domain, which makes up ~49% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~25–39 in this domain), expect 5–8 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
6concepts
Questions 6–10
- 6
A security operations team is evaluating a new log source. They notice that some log entries are missing timestamps and others have timestamps in different formats. Which data quality dimension is most directly affected?
Select an answer first - 7
A security team is considering how to collect logs from a legacy network device that does not support any modern logging protocols or agents. The device can only send syslog messages to a specific IP address. The team wants to integrate these logs into their SIEM. What is the most practical collection method?
Select an answer first - 8
A security operations team is integrating a new data source into its SIEM: endpoint telemetry from a Linux-based EDR agent. The team has already integrated Windows endpoint telemetry and network flow logs. The team notices that the Linux EDR agent sends data in a different format than the Windows agent, and the SIEM's correlation rules do not match the Linux data correctly. What is the most effective way to resolve this integration issue?
Select an answer first - 9
A security operations manager has implemented a new log collection pipeline for firewall logs. After a week, the manager wants to verify that the pipeline is functioning correctly. The SIEM shows a steady volume of logs, but the manager is concerned about silent data loss. Which validation method would best detect silent data loss?
Select an answer first - 10
A security operations manager is designing a detection strategy for a hybrid environment with on-premises servers and cloud workloads. The manager wants to detect unauthorized access to sensitive data stored in cloud storage. Which data source would provide the most direct visibility into this activity?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSOM” is a trademark of its owner, used for identification only.