GIAC GSOC Actual Free Exam Questions & Community Discussion
Which of the following is a common indicator of an endpoint compromise?
Response:
Response:
Correct Answer: D
Vote an answer
Which of these strategies should be employed to effectively share analytics insights with stakeholders?
Response:
Response:
Correct Answer: D
Vote an answer
What role does endpoint detection and response (EDR) software play in endpoint defense?
Response:
Response:
Correct Answer: C
Vote an answer
What is a primary goal of network traffic analysis in an enterprise environment?
Response:
Response:
Correct Answer: D
Vote an answer
In the context of SSH, what is a common attack method?
(Choose Three)
Response:
(Choose Three)
Response:
Correct Answer: A,B,C
Vote an answer
Your team has detected a significant increase in traffic to a DNS server, leading to degraded network performance. Upon investigation, you identify the traffic as part of a DNS amplification attack.
Which of the following steps should your team take to mitigate the attack and secure the DNS infrastructure?
(Choose Three)
Response:
Which of the following steps should your team take to mitigate the attack and secure the DNS infrastructure?
(Choose Three)
Response:
Correct Answer: A,B,C
Vote an answer
What is a proactive step in endpoint defense to detect vulnerabilities before they are exploited?
Response:
Response:
Correct Answer: A
Vote an answer
Which protocol is essential for establishing secure sessions over the internet and is a focus in network traffic analysis?
Response:
Response:
Correct Answer: A
Vote an answer
When analyzing HTTP(S) traffic, which two elements are crucial to identify potential attacks?
(Choose Two)
Response:
(Choose Two)
Response:
Correct Answer: B,C
Vote an answer
How does understanding the business context help in intrusion analysis?
Response:
Response:
Correct Answer: B
Vote an answer
You are a security analyst for an e-commerce company. Recently, customers have reported seeing strange pop-ups and being redirected to suspicious websites while browsing your company's website, even though HTTPS is enabled. Upon investigation, you discover that an attacker is performing an SSL strip attack, downgrading traffic from HTTPS to HTTP.
Which of the following steps should you take to mitigate this attack and secure user traffic?
(Choose Three)
Response:
Which of the following steps should you take to mitigate this attack and secure user traffic?
(Choose Three)
Response:
Correct Answer: C,D,E
Vote an answer
Which of the following are typical responsibilities of a Blue Team?
(Choose Two)
Response:
(Choose Two)
Response:
Correct Answer: A,B
Vote an answer
Which statement best describes the importance of SSL/TLS in HTTPS?
Response:
Response:
Correct Answer: B
Vote an answer
Your SOC team is struggling to keep up with the large volume of alerts generated by your SIEM system. Many alerts are low-priority, and the team is overwhelmed, leading to delayed response times for critical incidents. You have been tasked with improving the efficiency of the SIEM.
Which of the following actions should you take to optimize SIEM performance and reduce alert fatigue?
(Choose Three)
Response:
Which of the following actions should you take to optimize SIEM performance and reduce alert fatigue?
(Choose Three)
Response:
Correct Answer: A,C,E
Vote an answer
0
0
0
10
