Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Security Operations Manager

Domain 2Objective 1

Data Source Assessment and Collection GSOM Practice Questions (Page 6)

Part of the Detection and Response Operations domain, which makes up ~49% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~25–39 in this domain), expect 5–8 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)

37questions here
8free pages
6concepts

Questions 26–30

  1. 26application · medium

    A security operations team has configured a new data collection pipeline that ingests logs from a critical application server. After a week, the team suspects that the pipeline is not collecting all logs, as some expected events are missing from the SIEM. The team wants to validate the data collection and identify the root cause. What should the team do first?

    Select an answer first
  2. 27application · medium

    A security operations team is investigating a suspected data exfiltration incident. The team has access to firewall logs, DNS logs, and NetFlow data. During the investigation, they discover that the firewall logs only show the source and destination IP addresses and ports, while the DNS logs show the queried domain names. The NetFlow data shows the volume of traffic but not the content. The team needs to determine which specific files were transferred to an external IP address. Which data source assessment should the team make to address this gap?

    Select an answer first
  3. 28application · medium

    A security operations team is building a detection strategy for a new application that uses a microservices architecture. The application is deployed on a container orchestration platform. The team wants to ensure they have visibility into the application's behavior and can detect anomalies. Which data sources should the team prioritize for this environment?

    Select an answer first
  4. 29application · medium

    A security operations team is defining a data retention policy for a new SIEM. The team has identified the following data types: authentication logs, network flow data, and endpoint telemetry. The team has a storage budget that allows for a total of 10 terabytes of data. The team estimates that the authentication logs will generate 1 terabyte per month, the network flow data will generate 2 terabytes per month, and the endpoint telemetry will generate 3 terabytes per month. The team wants to retain authentication logs for 12 months, network flow data for 6 months, and endpoint telemetry for 3 months. What is the total storage requirement for this policy?

    Select an answer first
  5. 30application · medium

    A security team has configured a new data collection pipeline for endpoint logs using an agent-based collector. The team wants to ensure that the pipeline is working correctly and that no logs are being lost. The team has set up a test endpoint that generates a known set of test events. What is the most effective way to validate the collection pipeline?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSOM” is a trademark of its owner, used for identification only.