
GIAC Security Operations Manager
Domain 2Objective 2
Managing Alert Creation and Processing GSOM Practice Questions (Page 6)
Part of the Detection and Response Operations domain, which makes up ~49% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~25–39 in this domain), expect 5–8 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)
48questions here
10free pages
5concepts
Questions 26–30
- 26
A SOC manager is reviewing an alert that detects 'multiple failed logins followed by a successful login' for all user accounts. The alert currently has a threshold of 5 failed attempts within 10 minutes. The alert produces 200 alerts per day, and the SOC team is overwhelmed. Analysis shows that 90% of the alerts are for standard users who eventually log in successfully after a few typos. The remaining 10% involve privileged accounts. The SOC manager wants to reduce the volume while preserving detection of privileged-account compromise. Which approach best balances the trade-off?
Select an answer first - 27
A security operations team is implementing a new alert for suspicious PowerShell usage. The detection engineering lead has drafted a query that matches any PowerShell process execution with encoded command arguments. Before deploying this alert to production, the team wants to ensure it will not overwhelm the analysts with noise. Which step should the team take first?
Select an answer first - 28
A SOC manager is reviewing alert severity assignments. Currently, all alerts are set to High severity, causing analysts to treat them equally and potentially miss critical incidents. The manager wants to implement a more effective severity model. Which approach is the best trade-off?
Select an answer first - 29
An alert for 'multiple failed logins followed by a successful login' is generating hundreds of alerts per day, most of which are caused by a legacy application that retries authentication with a service account. The SOC manager wants to reduce the noise without losing detection of actual brute-force attacks. Which action is most appropriate?
Select an answer first - 30
A SOC is implementing a new alert for a critical vulnerability exploitation attempt. The alert will be monitored 24/7. The SOC manager needs to communicate the alert's purpose and response expectations to the on-call team. Which communication is most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSOM” is a trademark of its owner, used for identification only.