
GIAC Certified Detection Analyst
Domain 3Objective 1
Asset and Network Analytics GCDA Practice Questions (Page 2)
Part of the Network and Asset Analytics domain, which makes up ~24% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~12–19 in this domain), expect 6–10 from this objective — we provide 52 practice questions to prepare you well beyond it. (estimate)
52questions here
11free pages
12concepts
Questions 6–10
- 6
Which of the following is an example of an anomaly that might be detected?
Select an answer first - 7
A detection analyst is tasked with building an initial asset inventory for a segment that contains a mix of managed and unmanaged devices. The analyst has access to the existing DHCP logs, NetFlow data, and an active scanner. The network team warns that the segment contains several legacy medical devices that are known to crash when scanned aggressively. Which approach best balances completeness with safety?
Select an answer first - 8
A detection analyst is reviewing NetFlow data and notices that a workstation is sending a large amount of data to an external IP address during off-hours. The workstation is a standard user endpoint, and the external IP is not in any threat intelligence feed. The analyst has a baseline that shows this workstation normally sends less than 1 MB per day. Which conclusion is most appropriate?
Select an answer first - 9
A detection analyst is reviewing a packet capture and sees a series of TCP packets with the FIN and ACK flags set, sent from an internal host to an external IP. The packets are sent at a steady rate, and the external IP is not in any threat intelligence feed. Which interpretation is most appropriate?
Select an answer first - 10
An analyst is investigating a series of alerts. The firewall log shows outbound connections from a workstation to a known command-and-control (C2) domain. The DNS log shows the workstation resolving that domain. The endpoint detection log shows no malicious process on the workstation. The analyst must decide whether to escalate the incident. What is the most appropriate decision?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCDA” is a trademark of its owner, used for identification only.