
GIAC Security Operations Manager
Domain 2Objective 4
Managing Incident Response Execution GSOM Practice Questions (Page 9)
Part of the Detection and Response Operations domain, which makes up ~49% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~25–39 in this domain), expect 5–8 from this objective — we provide 54 practice questions to prepare you well beyond it. (estimate)
54questions here
11free pages
12concepts
Questions 41–45
- 41
A security operations manager has two active incidents: (1) a low-severity malware infection on a single test server that is not critical, and (2) a suspected data exfiltration from a finance database that may involve customer data. The SOC has limited staff and must allocate resources. Which incident should receive the most immediate attention?
Select an answer first - 42
What is the primary goal of a post-incident review (lessons learned)?
Select an answer first - 43
What is the primary purpose of providing structured status updates during an incident?
Select an answer first - 44
An organization is updating its incident response plan. Which component is ESSENTIAL to include to ensure clear decision-making during an incident?
Select an answer first - 45
What is the primary goal of a containment strategy during incident response?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSOM” is a trademark of its owner, used for identification only.