Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Detection Analyst

Domain 4Objective 2

Application and User Monitoring Analytics GCDA Practice Questions (Page 3)

Part of the Endpoint and User Analytics domain, which makes up ~25% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 7–10 from this objective — we provide 58 practice questions to prepare you well beyond it. (estimate)

58questions here
12free pages
13concepts

Questions 11–15

  1. 11expert · medium

    A company wants to create user behavior baselines to detect compromised accounts. They have historical data for all users, including login times, access patterns, and data transfer volumes. However, some users have very little historical data because they are new employees or have changed roles. What is the most effective approach to handle these users?

    Select an answer first
  2. 12expert · hard

    A critical business application is showing signs of a SQL injection attack. The application cannot be taken offline, but the attack must be contained. The security team has a WAF that can block specific signatures, but the application also uses legitimate dynamic queries that may match some signatures. Which response action best balances containment with business continuity?

    Select an answer first
  3. 13application · medium

    A security analyst is proactively hunting for threats that evade traditional detection. The analyst notices that a legitimate PDF viewer application, which normally opens files from the user's Documents folder, has recently been spawning PowerShell processes. Which hunting technique would best identify this as a potential indicator of compromise?

    Select an answer first
  4. 14expert · hard

    A security team wants to proactively hunt for a sophisticated attacker who is using legitimate applications to exfiltrate data. The attacker is likely to use a common cloud storage sync client. The team has SIEM data from endpoint logs and application logs. Which hunting approach is most likely to uncover the attacker?

    Select an answer first
  5. 15application · medium

    An application's logs show a pattern of repeated attempts to access a configuration file that is not normally accessed. The attempts are coming from a single user account that has never accessed this file before. The application is critical to business operations and cannot be taken offline. What is the best response?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCDA” is a trademark of its owner, used for identification only.