
GIAC Certified Detection Analyst
Domain 1Objective 3
Log Analysis and Alerting GCDA Practice Questions (Page 4)
Part of the SIEM Foundations domain, which makes up ~34% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~17–27 in this domain), expect 6–9 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
6concepts
Questions 16–20
- 16
An analyst is triaging an alert that fired when a user logged in from an IP address that is on a threat intelligence blocklist. The alert severity is 'medium'. The analyst checks the user's recent activity and sees that the user is currently on vacation and has not logged in from that IP before. What is the most appropriate action?
Select an answer first - 17
A company ingests logs from multiple sources: Windows Event Logs, Linux syslog, and custom application logs in JSON format. The SIEM normalizes all logs into a common schema with fields like 'src_ip', 'user', and 'event_type'. A correlation rule is written to detect multiple failed logins from the same source IP. Which normalization step is essential for this rule to work correctly across all log sources?
Select an answer first - 18
What is the primary function of a correlation rule in a SIEM?
Select an answer first - 19
An alert fires for a suspicious PowerShell command that downloads an executable from a known malicious IP. The alert includes the hostname, username, and the full command line. During triage, the analyst checks the host's recent logon events and sees that the user logged in interactively 30 minutes before the alert. The user is a system administrator. Which initial triage action is most appropriate?
Select an answer first - 20
A SIEM correlation rule detects a potential ransomware pattern: a user encrypting many files in a short period. The rule is set to severity 'critical' and sends an email to the security team. The team wants to ensure that this alert is acted upon immediately, even if the primary analyst is unavailable. Which configuration is most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCDA” is a trademark of its owner, used for identification only.