
GIAC Critical Controls Certification
Domain 5Objective 3
Network Monitoring and Defense GCCC Practice Questions (Page 2)
Part of the Security Operations and Monitoring domain, which makes up ~22% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~11–18 in this domain), expect 3–5 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)
46questions here
10free pages
8concepts
Questions 6–10
- 6
Which metric is most useful for evaluating the effectiveness of a security monitoring program?
Select an answer first - 7
What is the primary purpose of integrating threat intelligence feeds into security monitoring?
Select an answer first - 8
A security analyst is investigating a potential breach. The SIEM shows that a user logged in from an unusual location at 2 AM, and then a large amount of data was transferred to an external IP. The analyst needs to determine if the login was legitimate. Which log source would provide the most useful evidence?
Select an answer first - 9
A company wants to protect its internal web application from common web attacks such as SQL injection and cross-site scripting (XSS). The application is hosted on a server in the DMZ. Which network defense technology should be deployed to specifically filter malicious web traffic?
Select an answer first - 10
A security team is investigating a potential breach and needs to reconstruct the timeline of events across multiple systems. Which log management practice would be most helpful?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCCC” is a trademark of its owner, used for identification only.