
GIAC Certified Detection Analyst
Domain 4Objective 1
Endpoint Analytics GCDA Practice Questions (Page 3)
Part of the Endpoint and User Analytics domain, which makes up ~25% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 7–10 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)
43questions here
9free pages
5concepts
Questions 11–15
- 11
A security team is deploying endpoint detection analytics to a fleet of 5,000 endpoints. The team wants to ensure that the data is available for analysis even if the central SIEM is temporarily unavailable. Which collection strategy best meets this requirement?
Select an answer first - 12
What is the primary role of an endpoint agent in a centralized logging architecture?
Select an answer first - 13
A rule that alerts on 'powershell.exe making outbound network connections' is producing many false positives because administrators routinely use PowerShell for remote administration. Which tuning change best reduces false positives while still detecting malicious PowerShell?
Select an answer first - 14
A detection rule that flags PowerShell execution on endpoints is generating a high number of false positives because many administrators use PowerShell for legitimate automation. The analyst wants to reduce false positives while still detecting malicious PowerShell usage. Which tuning action is most appropriate?
Select an answer first - 15
Which action is most likely to reduce false positives for a rule that alerts on any PowerShell execution?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCDA” is a trademark of its owner, used for identification only.