
GIAC Certified Detection Analyst
Domain 4Objective 2
Application and User Monitoring Analytics GCDA Practice Questions (Page 7)
Part of the Endpoint and User Analytics domain, which makes up ~25% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 7–10 from this objective — we provide 58 practice questions to prepare you well beyond it. (estimate)
58questions here
12free pages
13concepts
Questions 31–35
- 31
What is the primary goal of leveraging analytics for threat hunting?
Select an answer first - 32
A user's account shows a login from a foreign IP at 2:00 AM, followed by a large data download. The user is a senior executive who frequently travels and sometimes logs in from foreign IPs at odd hours. The executive's assistant confirms the executive is on a business trip. Which response action is most appropriate?
Select an answer first - 33
A user who normally accesses the HR system only during business hours and only from the office suddenly logs in from a coffee shop IP at 11:00 PM and views the salary table. Which user behavior indicator most strongly suggests the account is compromised?
Select an answer first - 34
A web application's logs show a sudden spike in HTTP 500 errors, and the error messages contain SQL syntax fragments. The application is business-critical and must remain available. Which response action best balances containment with business continuity?
Select an answer first - 35
What does an application indicator of compromise (IOC) typically represent?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCDA” is a trademark of its owner, used for identification only.