Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Detection Analyst

Domain 2Objective 2

Defender and Sentinel Overview GCDA Practice Questions (Page 3)

Part of the Cloud and Microsoft Security Analytics domain, which makes up ~17% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 5–7 from this objective — we provide 36 practice questions to prepare you well beyond it. (estimate)

36questions here
8free pages
3concepts

Questions 11–15

  1. 11expert · hard

    A security team is deploying Microsoft Sentinel and must decide how to handle data from multiple regions. They have offices in the US and Europe, and data residency requirements mandate that European data remain in Europe. They also want to minimize cross-region data transfer costs. What should they do?

    Select an answer first
  2. 12expert · hard

    A security team is planning to deploy Microsoft Sentinel for a multi-cloud environment. They need to ingest logs from AWS, Azure, and on-premises sources. They also want to minimize the cost of data ingestion while retaining the ability to run complex queries. What should they consider?

    Select an answer first
  3. 13application · medium

    A security analyst needs to investigate a series of suspicious sign-ins across multiple cloud applications. They want to use a single query language to correlate sign-in logs with threat intelligence and other data sources. Which Sentinel feature should they use?

    Select an answer first
  4. 14application · medium

    A security operations team uses Microsoft Defender for Cloud to monitor a hybrid environment and wants to centralize alerts from all sources into a single analytics workspace. They also need to run custom KQL queries and create automated response playbooks. Which solution should they deploy?

    Select an answer first
  5. 15application · medium

    A SOC team wants to use Microsoft Sentinel to track the status of incidents and ensure they are assigned to the correct analysts. They also want to automate the assignment based on the incident type. What is the most efficient way to achieve this?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCDA” is a trademark of its owner, used for identification only.