
GIAC Security Operations Manager
Domain 2Objective 4
Managing Incident Response Execution GSOM Practice Questions (Page 7)
Part of the Detection and Response Operations domain, which makes up ~49% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~25–39 in this domain), expect 5–8 from this objective — we provide 54 practice questions to prepare you well beyond it. (estimate)
54questions here
11free pages
12concepts
Questions 31–35
- 31
After a malware outbreak, the incident response team has contained the affected systems and confirmed the malware has been removed. The team now needs to restore the systems to normal operation. Which action should the team take to ensure a secure recovery?
Select an answer first - 32
What is the purpose of maintaining a chain of custody for digital evidence?
Select an answer first - 33
Which containment strategy is most appropriate when an infected system must remain online to preserve evidence or maintain business operations?
Select an answer first - 34
Which metric measures the time between when an incident is first detected and when the response team begins to take action?
Select an answer first - 35
A security operations manager wants to measure the effectiveness of the incident response team. They have data on time to detect, time to respond, time to contain, and time to recover for several incidents. Which metric would BEST indicate the team's ability to minimize business impact?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSOM” is a trademark of its owner, used for identification only.