Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Critical Controls Certification

Domain 5Objective 3

Network Monitoring and Defense GCCC Practice Questions (Page 3)

Part of the Security Operations and Monitoring domain, which makes up ~22% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~11–18 in this domain), expect 3–5 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)

46questions here
10free pages
8concepts

Questions 11–15

  1. 11application · medium

    A network administrator suspects that a compromised host is communicating with a command-and-control (C2) server using a non-standard port and intermittent connections. Which monitoring technique would be most effective in detecting this behavior?

    Select an answer first
  2. 12application · medium

    A security operations center (SOC) receives alerts from multiple sources: firewall logs, IDS alerts, and endpoint detection and response (EDR) telemetry. The analysts are overwhelmed by the volume and often miss critical alerts. Which approach would most improve the efficiency and effectiveness of incident detection?

    Select an answer first
  3. 13expert · hard

    A SOC is evaluating two threat intelligence feeds: Feed A provides real-time indicators but has a high false-positive rate; Feed B provides curated, high-confidence indicators but with a 24-hour delay. The SOC needs to block an ongoing attack that is using rapidly changing infrastructure. Which feed should the SOC prioritize for automated blocking?

    Select an answer first
  4. 14expert · hard

    A SOC manager wants to improve the team's detection capabilities but has a limited budget. The team currently relies on free, open-source tools for network monitoring. Which investment would provide the most significant improvement in detection effectiveness?

    Select an answer first
  5. 15expert · hard

    A company is planning to segment its network to improve security. The network includes a mix of legacy systems that cannot be patched and modern systems. The security team wants to limit the risk from the legacy systems while maintaining business operations. Which segmentation strategy is most appropriate?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCCC” is a trademark of its owner, used for identification only.