
GIAC Certified Detection Analyst
Domain 3Objective 1
Asset and Network Analytics GCDA Practice Questions (Page 6)
Part of the Network and Asset Analytics domain, which makes up ~24% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~12–19 in this domain), expect 6–10 from this objective — we provide 52 practice questions to prepare you well beyond it. (estimate)
52questions here
11free pages
12concepts
Questions 26–30
- 26
An analyst is establishing a network baseline for a new office location. The office has just opened and has been operational for two days. The analyst wants to detect anomalies as soon as possible. What is the most appropriate approach to baseline establishment?
Select an answer first - 27
An organization is integrating a commercial threat intelligence feed into its SIEM. The feed contains a large number of IP addresses that are flagged as malicious. The analyst notices that several internal IP addresses are also present in the feed, which are clearly not malicious. What is the most appropriate way to handle this?
Select an answer first - 28
A vulnerability scan of a hospital network has identified multiple assets with critical vulnerabilities. The assets include an MRI machine, a patient records database, and a guest Wi-Fi access point. The analyst must prioritize remediation. Which asset should be remediated first?
Select an answer first - 29
What is the main purpose of log and event correlation?
Select an answer first - 30
What is the purpose of classifying assets by criticality?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCDA” is a trademark of its owner, used for identification only.