
GIAC Security Operations Manager
Domain 2Objective 4
Managing Incident Response Execution GSOM Practice Questions (Page 4)
Part of the Detection and Response Operations domain, which makes up ~49% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~25–39 in this domain), expect 5–8 from this objective — we provide 54 practice questions to prepare you well beyond it. (estimate)
54questions here
11free pages
12concepts
Questions 16–20
- 16
An organization is updating its incident response plan. The plan must ensure that during a major incident, the right people make decisions and communication flows effectively. What is the MOST important component to include?
Select an answer first - 17
During a prolonged incident, the incident commander must provide regular updates to multiple stakeholders, including executives, legal counsel, and the technical response team. The stakeholders have different information needs. Which communication strategy is most effective?
Select an answer first - 18
A security operations manager wants to evaluate the effectiveness of the incident response team's detection capabilities. Which metric is most appropriate for this purpose?
Select an answer first - 19
What is the primary objective of the recovery phase in incident response?
Select an answer first - 20
Which metric is most directly related to the goal of minimizing business disruption?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSOM” is a trademark of its owner, used for identification only.