
GIAC Certified Detection Analyst
Domain 1Objective 3
Log Analysis and Alerting GCDA Practice Questions (Page 3)
Part of the SIEM Foundations domain, which makes up ~34% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~17–27 in this domain), expect 6–9 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
6concepts
Questions 11–15
- 11
A company is ingesting firewall logs that contain the source IP, destination IP, and port. The logs are in a proprietary format that the SIEM does not recognize. The SIEM has a built-in parser for common firewall vendors, but this vendor is not supported. What is the most appropriate step to enable analysis of these logs?
Select an answer first - 12
A correlation rule is designed to detect a brute-force attack. Which condition would the rule most likely use?
Select an answer first - 13
A SIEM has a correlation rule that triggers when a user logs in from a new device and then accesses a sensitive file share within 5 minutes. The rule is generating many alerts because users often switch devices. The analyst wants to reduce false positives while still detecting potential credential theft. Which change to the rule logic is most appropriate?
Select an answer first - 14
A SOC has a rule that alerts on any user who logs in from more than 3 different countries within a 24-hour period. The rule generates many false positives for employees who travel frequently. The SOC wants to reduce false positives without missing real impossible travel attacks. Which tuning approach is most effective?
Select an answer first - 15
A SIEM rule is designed to detect lateral movement by alerting when a user logs into more than 5 different hosts within 10 minutes. The rule is generating a high volume of alerts from a legitimate automation tool that uses a service account to run scripts across many servers. The security team wants to reduce false positives without missing real lateral movement. The automation tool's IP addresses are known and static. Which tuning approach best balances detection and noise reduction?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCDA” is a trademark of its owner, used for identification only.