Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Security Operations Manager

Domain 2Objective 2

Managing Alert Creation and Processing GSOM Practice Questions (Page 2)

Part of the Detection and Response Operations domain, which makes up ~49% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~25–39 in this domain), expect 5–8 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)

48questions here
10free pages
5concepts

Questions 6–10

  1. 6application · medium

    A security engineer is tasked with creating an alert for detecting 'credential dumping' on Windows endpoints. The engineer has identified the relevant event IDs and has a draft detection rule. What is the next step in the alert creation workflow?

    Select an answer first
  2. 7expert · hard

    A SOC has a large backlog of open alerts. Many are low-priority and have been open for weeks. The SOC manager wants to reduce the backlog without increasing risk. Which strategy is the best trade-off?

    Select an answer first
  3. 8expert · hard

    A SOC manager is reviewing an alert that detects 'unusual outbound connection to a cloud storage service'. The alert fires for a developer who uses a personal cloud storage account to share large files with a client. The developer's activity is legitimate but violates company policy. The SOC manager wants to reduce false positives while still detecting policy violations and potential exfiltration. Which approach best balances these concerns?

    Select an answer first
  4. 9application · medium

    A SOC manager is reviewing the documentation for a newly created alert that detects suspicious logon behavior. The alert documentation currently lists the rule name, the triggering condition, and the severity. Which additional element is most important to include for effective communication to on-call analysts?

    Select an answer first
  5. 10expert · hard

    A SOC has an alert that detects 'suspicious PowerShell activity' and it fires frequently for a legitimate IT automation script. The SOC manager wants to reduce false positives but is concerned that suppressing the script entirely could hide malicious use of the same script. The script is signed by the IT department and runs from a specific server. Which approach best balances false-positive reduction and detection of malicious use?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSOM” is a trademark of its owner, used for identification only.