
GIAC Security Operations Manager
Domain 2Objective 5
Preparing for Incident Response GSOM Practice Questions (Page 5)
Part of the Detection and Response Operations domain, which makes up ~49% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~25–39 in this domain), expect 5–8 from this objective — we provide 54 practice questions to prepare you well beyond it. (estimate)
54questions here
11free pages
8concepts
Questions 21–25
- 21
A security operations manager is preparing for potential incidents that may involve criminal activity. The organization wants to ensure that evidence is preserved in a way that supports potential legal action. Which action is most important to take during the preparation phase?
Select an answer first - 22
Which of the following is a key component of incident response preparation?
Select an answer first - 23
A security manager is designing an incident response training program. The program must ensure that team members can effectively execute their roles during a high-pressure incident. The team has limited time for training. Which training method is most effective?
Select an answer first - 24
During a ransomware incident, the incident response team needs to quickly determine which systems are affected and preserve evidence. The team includes a forensic analyst, a network engineer, and a legal advisor. Which additional role is most critical to add to the team to support this effort?
Select an answer first - 25
What is a key benefit of coordinating with external vendors (e.g., security tool providers) during incident response preparation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSOM” is a trademark of its owner, used for identification only.