
GIAC Critical Controls Certification
Domain 5Objective 3
Network Monitoring and Defense GCCC Practice Questions (Page 1)
Part of the Security Operations and Monitoring domain, which makes up ~22% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~11–18 in this domain), expect 3–5 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)
46questions here
10free pages
8concepts
Questions 1–5
- 1
A SOC manager is reviewing the effectiveness of their intrusion detection system (IDS). The IDS generates a high volume of alerts, but only a small percentage are confirmed as true positives. The team is spending too much time on false positives. Which metric would best help the manager understand the quality of the IDS alerts?
Select an answer first - 2
Which type of threat intelligence focuses on the specific tools and methods used by a particular threat actor?
Select an answer first - 3
Which access control mechanism is commonly used to enforce segmentation between network zones?
Select an answer first - 4
An organization has detected a worm that is spreading rapidly across its internal network. The worm uses multiple propagation methods, including SMB and RDP. The incident response team needs to contain the worm quickly while minimizing business disruption. Which containment strategy is most effective?
Select an answer first - 5
A security team wants to improve its network monitoring by reducing the number of false positives. They have a SIEM with many correlation rules. Which approach is most effective for reducing false positives without losing true positives?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCCC” is a trademark of its owner, used for identification only.