Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Detection Analyst

Domain 4Objective 1

Endpoint Analytics GCDA Practice Questions (Page 5)

Part of the Endpoint and User Analytics domain, which makes up ~25% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 7–10 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)

43questions here
9free pages
5concepts

Questions 21–25

  1. 21foundation · easy

    Which analytical technique is most appropriate for linking a suspicious process execution on one host to a subsequent authentication event on another host?

    Select an answer first
  2. 22expert · hard

    An organization has a detection rule that flags any process that writes to the startup folder. The rule is generating a high volume of alerts, but the security team has limited analyst time. They want to reduce the alert volume while still detecting malicious persistence. The organization has a known set of approved applications that write to the startup folder during installation. Which tuning approach best balances reducing false positives and maintaining detection coverage?

    Select an answer first
  3. 23expert · hard

    A security team manages 5,000 endpoints across multiple sites. They need to collect process, network, and file events for detection, but the central SIEM has limited ingestion capacity. The team must prioritize which events to send. Which approach best balances detection coverage with SIEM capacity?

    Select an answer first
  4. 24expert · hard

    A security team has a detection rule that flags any use of PsExec on endpoints. The rule generates many false positives because system administrators use PsExec for legitimate remote administration. The team wants to reduce false positives while still detecting malicious use of PsExec. They have a list of known administrative accounts and a list of approved administrative workstations. Which tuning approach is most effective?

    Select an answer first
  5. 25application · medium

    A detection rule flags any process that creates a file in the Windows startup folder. The rule generates hundreds of alerts per day because a legitimate software updater writes there during routine patching. Which tuning action is most effective while preserving detection of malicious persistence?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCDA” is a trademark of its owner, used for identification only.