
GIAC Certified Detection Analyst
Domain 3Objective 1
Asset and Network Analytics GCDA Practice Questions (Page 9)
Part of the Network and Asset Analytics domain, which makes up ~24% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~12–19 in this domain), expect 6–10 from this objective — we provide 52 practice questions to prepare you well beyond it. (estimate)
52questions here
11free pages
12concepts
Questions 41–45
- 41
What is the purpose of establishing a network baseline?
Select an answer first - 42
An analyst is investigating a potential compromise. The analyst sees a firewall log showing outbound connections from an internal workstation to a known malicious IP on port 443. The analyst also sees a DNS log showing a query for a domain that resolves to that IP. What is the most appropriate next step?
Select an answer first - 43
A detection analyst is investigating a series of alerts. The analyst has the following data: an authentication log showing a successful login from a foreign IP address, a NetFlow record showing a large data transfer from the same workstation to that IP, and a threat intelligence feed that lists the IP as a known command-and-control server. Which action is most appropriate?
Select an answer first - 44
Which factor is most important when prioritizing vulnerability remediation?
Select an answer first - 45
What is the primary purpose of asset vulnerability assessment?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCDA” is a trademark of its owner, used for identification only.