
GIAC Security Operations Manager
Domain 2Objective 2
Managing Alert Creation and Processing GSOM Practice Questions (Page 8)
Part of the Detection and Response Operations domain, which makes up ~49% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~25–39 in this domain), expect 5–8 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)
48questions here
10free pages
5concepts
Questions 36–40
- 36
A SOC manager is preparing to communicate a new critical alert to stakeholders. The alert detects a specific zero-day exploit that is actively being used in the wild. The SOC manager must decide how to communicate the alert to different audiences. Which communication strategy is most effective?
Select an answer first - 37
A security operations team is building a new alert to detect multiple failed logins followed by a successful login on a domain controller. The detection engineer proposes a rule that triggers whenever the count of failed logins exceeds five within 10 minutes, regardless of the source or target account. The SOC manager reviews the rule and wants to reduce false positives while keeping the detection meaningful. Which adjustment should the SOC manager prioritize?
Select an answer first - 38
An alert designed to detect 'pass-the-hash' activity is producing a high number of alerts from a legitimate administrative tool that uses similar authentication methods. The SOC manager wants to reduce false positives while maintaining detection of actual attacks. Which approach is most effective?
Select an answer first - 39
A SOC analyst is creating an alert for the use of Mimikatz on a domain controller. The alert will fire when the process name matches and command-line arguments indicate credential dumping. The SOC manager must assign a severity level. Which severity assignment is most appropriate for this alert?
Select an answer first - 40
A SOC analyst discovers an alert indicating that a domain administrator account was used to log in from an unfamiliar external IP address at 3:00 AM. The organization has no remote access policy that would explain this login. What severity level should the analyst assign to this alert?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSOM” is a trademark of its owner, used for identification only.