
GIAC Certified Detection Analyst
Domain 4Objective 2
Application and User Monitoring Analytics GCDA Practice Questions (Page 12)
Part of the Endpoint and User Analytics domain, which makes up ~25% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 7–10 from this objective — we provide 58 practice questions to prepare you well beyond it. (estimate)
58questions here
12free pages
13concepts
Questions 56–58
- 56
A web application's logs show a pattern of SQL injection attempts from a single IP address. The attempts are increasing in frequency and complexity, but none have been successful so far. The application is critical to business operations and cannot be taken offline. What is the best response?
Select an answer first - 57
A company's finance application normally logs 200–400 failed login attempts per day from various IPs. Over the past hour, the SIEM shows 5,000 failed logins from a single IP, followed by a successful login from that IP. The user account then executed a SQL query that returned 10,000 rows from a customer table. Which two data sources, when correlated, most directly confirm the attack chain?
Select an answer first - 58
Which activity is an example of using analytics for threat hunting?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GCDA
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCDA” is a trademark of its owner, used for identification only.