Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Security Operations Manager

Domain 2Objective 4

Managing Incident Response Execution GSOM Practice Questions (Page 2)

Part of the Detection and Response Operations domain, which makes up ~49% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~25–39 in this domain), expect 5–8 from this objective — we provide 54 practice questions to prepare you well beyond it. (estimate)

54questions here
11free pages
12concepts

Questions 6–10

  1. 6application · medium

    During an incident, the incident response team collects a hard drive from a compromised server. The team plans to send the drive to law enforcement for forensic analysis. Which action is essential to maintain the chain of custody?

    Select an answer first
  2. 7foundation · easy

    Which of the following is an example of a structured incident report?

    Select an answer first
  3. 8foundation · easy

    Which combination of factors is most commonly used to classify an incident's severity?

    Select an answer first
  4. 9expert · hard

    After a major incident, the incident response team conducts a post-incident review. The team identifies that the time to detect was longer than expected. What is the MOST effective action to improve future detection?

    Select an answer first
  5. 10foundation · easy

    In an incident response plan, what is the primary purpose of defining escalation paths?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSOM” is a trademark of its owner, used for identification only.