
GIAC Security Operations Manager
Domain 2Objective 3
Proactive Detection and Analysis GSOM Practice Questions (Page 2)
Part of the Detection and Response Operations domain, which makes up ~49% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~25–39 in this domain), expect 5–8 from this objective — we provide 52 practice questions to prepare you well beyond it. (estimate)
52questions here
11free pages
7concepts
Questions 6–10
- 6
After a security incident, the post-incident review reveals that the malicious activity was present in the environment for 45 days before detection. The detection team wants to implement a continuous improvement loop to reduce dwell time. Which action is most aligned with this goal?
Select an answer first - 7
What is the primary purpose of proactive detection in a security operations center?
Select an answer first - 8
A SOC manager wants to reduce the average dwell time of threats in the environment. The current detection approach relies primarily on signature-based alerts from the SIEM. Which change would most directly support proactive detection and reduce dwell time?
Select an answer first - 9
What is the purpose of a continuous improvement loop in detection operations?
Select an answer first - 10
After a security incident, the SOC team reviews the detection rules that fired and finds that several rules had high false-positive rates, while one critical attack path was not detected at all. The team wants to establish a continuous improvement loop. Which action best supports this goal?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSOM” is a trademark of its owner, used for identification only.