
GIAC Critical Controls Certification
Domain 5Objective 3
Network Monitoring and Defense GCCC Practice Questions (Page 4)
Part of the Security Operations and Monitoring domain, which makes up ~22% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~11–18 in this domain), expect 3–5 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)
46questions here
10free pages
8concepts
Questions 16–20
- 16
Which log analysis technique is used to identify patterns that may indicate a coordinated attack?
Select an answer first - 17
Which response action is taken to prevent an ongoing attack from spreading further?
Select an answer first - 18
During routine monitoring, a SOC analyst notices a large volume of traffic from an internal server to an external IP address on port 22 (SSH) at unusual hours. The server is not supposed to initiate SSH connections. What should the analyst do first?
Select an answer first - 19
What is the primary function of an intrusion prevention system (IPS) in network defense?
Select an answer first - 20
A company's log management system is receiving logs from multiple sources, but the logs have inconsistent timestamp formats and timezone offsets. This makes correlation difficult. What is the most effective solution?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCCC” is a trademark of its owner, used for identification only.