
GIAC Security Operations Manager
Domain 3Objective 2
SOC Analytics and Metrics GSOM Practice Questions (Page 7)
Part of the Performance and Improvement domain, which makes up ~20% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 5–8 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
7concepts
Questions 31–35
- 31
A SOC manager finds that the 'percentage of alerts that are true positives' has been declining for six months. The SOC has not changed its detection rules or tooling. What is the most likely cause?
Select an answer first - 32
Which metric is commonly used to measure the efficiency of a SOC's incident detection process?
Select an answer first - 33
A SOC manager wants to compute the false positive rate for the team's detection rules. The SIEM contains alert records, but the analyst disposition (true positive vs. false positive) is recorded in a separate ticketing system. What is the most reliable way to collect the data needed for this metric?
Select an answer first - 34
A SOC manager notices that the number of incidents has decreased by 30% over the past quarter, but the mean time to detect (MTTD) has increased by 50%. The manager suspects that the decrease in incidents is due to a change in detection rules. What is the most appropriate interpretation?
Select an answer first - 35
After analyzing monthly metrics, a SOC manager identifies that Mean Time to Respond (MTTR) has increased due to delays in the escalation process. What is the most appropriate improvement action?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSOM” is a trademark of its owner, used for identification only.