
GIAC Security Operations Manager
Domain 2Objective 4
Managing Incident Response Execution GSOM Practice Questions (Page 3)
Part of the Detection and Response Operations domain, which makes up ~49% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~25–39 in this domain), expect 5–8 from this objective — we provide 54 practice questions to prepare you well beyond it. (estimate)
54questions here
11free pages
12concepts
Questions 11–15
- 11
Which action is part of the eradication phase of incident response?
Select an answer first - 12
A company experiences a data breach involving personal data of EU residents. The incident response team is preparing to notify affected individuals. Which requirement must the team consider?
Select an answer first - 13
A security operations manager wants to evaluate the effectiveness of the incident response team. Which metric would BEST indicate how quickly the team can contain an incident?
Select an answer first - 14
A company discovers that a cybercriminal has stolen customer personal data from its database. The company's legal counsel advises that the breach may trigger a state data breach notification law. Which action should the incident response team take regarding law enforcement?
Select an answer first - 15
A company discovers a breach involving personal data of EU residents. The incident response team is preparing to notify affected individuals. What legal requirement must they consider FIRST?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSOM” is a trademark of its owner, used for identification only.