
GIAC Certified Detection Analyst
Domain 4Objective 1
Endpoint Analytics GCDA Practice Questions (Page 9)
Part of the Endpoint and User Analytics domain, which makes up ~25% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 7–10 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)
43questions here
9free pages
5concepts
Questions 41–43
- 41
A detection rule that alerts on the creation of new local admin accounts is generating false positives because a legitimate IT tool creates temporary admin accounts during maintenance. The analyst wants to reduce false positives without missing real creation of admin accounts. Which action is most appropriate?
Select an answer first - 42
An organization wants to detect unauthorized changes to critical system binaries. Which endpoint data source is most directly suited for this detection?
Select an answer first - 43
A security team is deploying endpoint detection analytics to a remote workforce. The endpoints are laptops that are often offline and connect via VPN. The team needs to ensure that endpoint data is available for analysis in the SIEM, but they also need to minimize the impact on the laptops' performance and battery life. Which collection strategy best meets these conflicting requirements?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GCDA
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCDA” is a trademark of its owner, used for identification only.