Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Detection Analyst

Domain 3Objective 1

Asset and Network Analytics GCDA Practice Questions (Page 5)

Part of the Network and Asset Analytics domain, which makes up ~24% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~12–19 in this domain), expect 6–10 from this objective — we provide 52 practice questions to prepare you well beyond it. (estimate)

52questions here
11free pages
12concepts

Questions 21–25

  1. 21application · medium

    A detection analyst has established a baseline for a database server that normally receives about 100 queries per minute from a specific application server. The analyst observes a sudden increase to 10,000 queries per minute from the same application server. Which action should the analyst take first?

    Select an answer first
  2. 22foundation · easy

    Which of the following is typically represented in a network topology map?

    Select an answer first
  3. 23foundation · easy

    Which protocol is used to resolve domain names to IP addresses and is often abused for data exfiltration or DNS tunneling?

    Select an answer first
  4. 24expert · hard

    A large organization is classifying assets for monitoring priority. The assets include a domain controller, a file server containing sensitive HR data, a public web server, and a development server. The organization has limited monitoring resources and must prioritize. The domain controller is in a highly restricted administrative network, the file server is accessible to all employees, the web server is internet-facing, and the development server is isolated. Which asset should receive the highest monitoring priority?

    Select an answer first
  5. 25expert · hard

    A detection analyst is integrating a new threat intelligence feed that contains a large number of IP addresses. The analyst notices that many of the IPs are cloud provider ranges and are frequently used by legitimate services. Which approach would best reduce false positives while still detecting malicious activity?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCDA” is a trademark of its owner, used for identification only.