
GIAC Critical Controls Certification
Domain 5Objective 1
Audit Log Management GCCC Practice Questions (Page 10)
Part of the Security Operations and Monitoring domain, which makes up ~22% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~11–18 in this domain), expect 3–5 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)
49questions here
10free pages
8concepts
Questions 46–49
- 46
A company is subject to a regulation that requires audit logs to be retained for at least one year, but also requires that logs be available for immediate review upon request. The company has limited storage budget. Which retention policy best meets both requirements?
Select an answer first - 47
During an incident investigation, an analyst needs to determine whether an attacker moved laterally from a compromised workstation to a database server. Which set of log sources would provide the most definitive evidence of lateral movement?
Select an answer first - 48
A security team is designing a new audit log management program. They want to ensure that log sources are consistently configured, that retention periods are documented, and that logs are protected from tampering. Which set of actions best aligns with audit log management best practices?
Select an answer first - 49
A company has a mix of on-premises servers and cloud-based applications. The security team wants a single view of audit logs from both environments for incident response. Which approach is the most effective?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GCCC
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCCC” is a trademark of its owner, used for identification only.