Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Detection Analyst

Domain 1Objective 3

Log Analysis and Alerting GCDA Practice Questions (Page 2)

Part of the SIEM Foundations domain, which makes up ~34% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~17–27 in this domain), expect 6–9 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)

44questions here
9free pages
6concepts

Questions 6–10

  1. 6application · medium

    A company collects logs from Linux servers, Windows servers, and network appliances. The SIEM is receiving them in different formats: syslog for Linux, Windows Event Log for Windows, and vendor-specific formats for network devices. The detection team wants to write a single correlation rule that checks for failed login attempts across all sources. What should be done to enable this rule?

    Select an answer first
  2. 7foundation · easy

    During alert triage, what is the primary goal when determining whether an alert is a false positive?

    Select an answer first
  3. 8foundation · easy

    A SIEM rule generates a high volume of alerts for a routine administrative activity. What is the most effective way to reduce this noise while still detecting genuine threats?

    Select an answer first
  4. 9expert · hard

    A SOC is investigating a series of alerts where a user's account is locked out multiple times, followed by a successful login from a different country. The SIEM has a rule that triggers on account lockouts and another rule that triggers on impossible travel. The team is receiving duplicate alerts for the same incident. What is the most effective way to reduce alert fatigue while maintaining detection fidelity?

    Select an answer first
  5. 10application · medium

    A company is ingesting logs from a custom application that writes timestamps in a non-standard format (e.g., '2025-03-01 14:30:22 UTC'). The SIEM is unable to correlate these events with other logs because the timestamp field is not recognized. What is the most effective way to fix this?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCDA” is a trademark of its owner, used for identification only.