
GIAC Critical Controls Certification
Domain 5Objective 1
Audit Log Management GCCC Practice Questions (Page 8)
Part of the Security Operations and Monitoring domain, which makes up ~22% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~11–18 in this domain), expect 3–5 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)
49questions here
10free pages
8concepts
Questions 36–40
- 36
A company operates 200 Linux servers and 50 network switches across three data centers. The security team needs a centralized audit log repository that can accept syslog from the switches and a custom JSON format from the servers, while also ensuring that logs cannot be altered by an attacker who compromises a single server. Which approach best meets these requirements?
Select an answer first - 37
A security analyst notices that a user's account successfully authenticated to the VPN at 02:00, then logged into a database server at 02:05, and then accessed a sensitive file share at 02:10. The user's normal working hours are 09:00 to 17:00. Which analysis technique would most directly flag this activity as suspicious?
Select an answer first - 38
A security team is investigating a breach and discovers that an attacker with root access on a Linux server modified the local audit logs to hide their activities. The server was configured to send logs to a central log collector via syslog over UDP. The central collector has logs that do not match the local logs. Why might the central logs be considered more trustworthy?
Select an answer first - 39
A healthcare organization must retain audit logs for six years to meet HIPAA requirements. They currently store logs in a hot-tier SIEM for 90 days, then move them to a cold storage bucket. The compliance officer is concerned that logs older than 90 days are not easily searchable for e-discovery requests. The security team wants to minimize costs while ensuring logs remain tamper-evident. Which approach best balances these needs?
Select an answer first - 40
Which of the following is a common source of audit logs in a security architecture?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCCC” is a trademark of its owner, used for identification only.