
GIAC Security Operations Manager
Domain 2Objective 3
Proactive Detection and Analysis GSOM Practice Questions (Page 4)
Part of the Detection and Response Operations domain, which makes up ~49% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~25–39 in this domain), expect 5–8 from this objective — we provide 52 practice questions to prepare you well beyond it. (estimate)
52questions here
11free pages
7concepts
Questions 16–20
- 16
A threat hunter is reviewing network flow data and notices that a small number of internal hosts are communicating with a newly registered domain that has no historical presence in the environment. The hunter wants to determine if this is malicious. Which next step best applies hypothesis-driven analysis?
Select an answer first - 17
A SOC analyst is reviewing a series of alerts that show a pattern: an attacker is using a legitimate remote management tool (RMM) to move laterally across the network. The analyst recognizes this as a 'living off the land' technique. Which proactive action is most appropriate?
Select an answer first - 18
A detection engineer is designing a rule to detect 'unusual outbound data transfers' from a server that normally sends less than 100 MB per day. The rule must minimize false positives while catching exfiltration. The engineer has access to NetFlow and proxy logs. Which approach best balances fidelity and coverage?
Select an answer first - 19
An organization wants to improve its proactive detection capabilities by integrating new data sources. Currently, they collect Windows event logs and firewall logs, but they lack visibility into DNS queries and endpoint process command lines. Which data source integration would most directly enhance the ability to detect command-and-control (C2) communication and malicious process execution?
Select an answer first - 20
An analyst is reviewing a series of alerts that show a user account attempting to log in from multiple geographic locations within a short time period. The analyst also notices that the account recently had its password reset. Which attack pattern is most likely indicated by these observations?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSOM” is a trademark of its owner, used for identification only.