
GIAC Security Operations Manager
Domain 2Objective 4
Managing Incident Response Execution GSOM Practice Questions (Page 2)
Part of the Detection and Response Operations domain, which makes up ~49% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~25–39 in this domain), expect 5–8 from this objective — we provide 54 practice questions to prepare you well beyond it. (estimate)
54questions here
11free pages
12concepts
Questions 6–10
- 6
During an incident, the incident response team collects a hard drive from a compromised server. The team plans to send the drive to law enforcement for forensic analysis. Which action is essential to maintain the chain of custody?
Select an answer first - 7
Which of the following is an example of a structured incident report?
Select an answer first - 8
Which combination of factors is most commonly used to classify an incident's severity?
Select an answer first - 9
After a major incident, the incident response team conducts a post-incident review. The team identifies that the time to detect was longer than expected. What is the MOST effective action to improve future detection?
Select an answer first - 10
In an incident response plan, what is the primary purpose of defining escalation paths?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSOM” is a trademark of its owner, used for identification only.