Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Security Operations Manager

Domain 1Objective 3

SOC Tools and Technology GSOM Practice Questions (Page 1)

Part of the SOC Strategy and Architecture domain, which makes up ~31% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~16–25 in this domain), expect 5–8 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)

40questions here
8free pages
5concepts

Questions 1–5

  1. 1expert · hard

    A SOC manager must select a new SIEM. The organization has a strict data residency requirement: all security logs must remain in the country where the company operates. The company also expects to triple its log volume in the next year. Two vendors are shortlisted: Vendor A offers a cloud SIEM with a data center in the required country but limited storage expansion options. Vendor B offers an on-premises SIEM with unlimited storage but requires significant hardware investment and a longer deployment time. Which choice best balances the constraints?

    Select an answer first
  2. 2foundation · easy

    A security operations center (SOC) analyst needs to centralize and correlate logs from firewalls, endpoints, and cloud services to detect potential security incidents. Which category of SOC tool is specifically designed for this purpose?

    Select an answer first
  3. 3application · medium

    A SOC receives hundreds of low-severity alerts daily. Analysts spend most of their time verifying whether alerts are true positives. The manager wants to reduce analyst workload without increasing the risk of missing genuine threats. Which approach is most effective?

    Select an answer first
  4. 4expert · hard

    A SOC manager wants to automate the response to a common alert type. The SOAR playbook will block the source IP on the firewall and reset the affected user's password. However, the firewall team is concerned about blocking a shared IP address that could affect multiple users. What is the best way to handle this in the playbook?

    Select an answer first
  5. 5foundation · easy

    A SOC manager wants to reduce the time it takes to contain a common malware outbreak by automatically isolating affected endpoints and blocking the malicious IP address. Which approach best achieves this goal?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSOM” is a trademark of its owner, used for identification only.