
GIAC Certified Detection Analyst
Domain 4Objective 1
Endpoint Analytics GCDA Practice Questions (Page 8)
Part of the Endpoint and User Analytics domain, which makes up ~25% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 7–10 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)
43questions here
9free pages
5concepts
Questions 36–40
- 36
A detection engineer wants to detect a specific malware family that always writes a file with a known name to the %TEMP% directory and then executes it. Which analytical technique is most efficient for this known indicator?
Select an answer first - 37
Which endpoint detection use case is most directly associated with a process running with higher privileges than the user who launched it?
Select an answer first - 38
Which analytical technique involves establishing a normal pattern of behavior and then flagging deviations from that pattern?
Select an answer first - 39
A detection engineer is building an anomaly detection model for process executions. The environment has a mix of servers with stable workloads and user workstations with highly variable activity. The model must minimize false positives while still detecting true anomalies. Which approach is most appropriate?
Select an answer first - 40
A company has a mix of Windows and Linux endpoints. The security team needs to collect process, file system, and network connection data from all endpoints into a central SIEM for detection analytics. The endpoints are a mix of cloud VMs and on-premises workstations. Which approach best meets the collection requirement?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCDA” is a trademark of its owner, used for identification only.