Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Detection Analyst

Domain 2Objective 2

Defender and Sentinel Overview GCDA Practice Questions (Page 4)

Part of the Cloud and Microsoft Security Analytics domain, which makes up ~17% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 5–7 from this objective — we provide 36 practice questions to prepare you well beyond it. (estimate)

36questions here
8free pages
3concepts

Questions 16–20

  1. 16application · medium

    An organization uses Microsoft Defender for Endpoint and Microsoft Sentinel. The security team wants to enrich Sentinel incidents with the full device timeline from Defender for Endpoint when an incident is created. What is the recommended approach?

    Select an answer first
  2. 17application · medium

    A company wants to protect its Azure SQL databases and storage accounts from threats. They also want to centralize the security alerts from these resources in a single dashboard. Which Microsoft Defender product should they use?

    Select an answer first
  3. 18application · medium

    A company uses Microsoft Defender for Cloud to assess the security posture of its Azure subscriptions. The security team wants to view a unified score that reflects the implementation of recommended security controls across all subscriptions. Which Defender for Cloud feature should they use?

    Select an answer first
  4. 19application · medium

    A security operations center (SOC) wants to use Microsoft Sentinel to detect a known attack pattern that involves multiple data sources, such as Azure AD sign-ins, AWS CloudTrail, and endpoint events. They need to create a custom detection that triggers an incident when the pattern is observed. What should they do?

    Select an answer first
  5. 20expert · hard

    A security team is deploying Microsoft Sentinel and needs to ensure that sensitive data, such as usernames and IP addresses, is not exposed to all analysts. They want to restrict access to specific tables and columns while still allowing the SOC to perform investigations. What should they do?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCDA” is a trademark of its owner, used for identification only.