
GIAC Critical Controls Certification
Domain 5Objective 3
Network Monitoring and Defense GCCC Practice Questions (Page 5)
Part of the Security Operations and Monitoring domain, which makes up ~22% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~11–18 in this domain), expect 3–5 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)
46questions here
10free pages
8concepts
Questions 21–25
- 21
A security operations center (SOC) is planning to implement a network monitoring program. They have limited staff and budget. Which approach provides the best balance of coverage and cost?
Select an answer first - 22
A SOC manager wants to demonstrate the value of the monitoring program to executives. Which metric would best show the reduction in risk due to monitoring?
Select an answer first - 23
Which technique is used to detect anomalies by establishing a baseline of normal network behavior?
Select an answer first - 24
A SOC is considering integrating a commercial threat intelligence feed that provides IP and domain indicators. The feed has a high false-positive rate, and the SOC is already overwhelmed with alerts. How should the SOC proceed to improve detection without increasing alert fatigue?
Select an answer first - 25
A security operations center (SOC) receives a threat intelligence feed that lists a set of malicious IP addresses. The SOC wants to detect any internal host communicating with these IPs. Which log source is most directly useful for this detection?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCCC” is a trademark of its owner, used for identification only.