Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Detection Analyst

Domain 1Objective 3

Log Analysis and Alerting GCDA Practice Questions (Page 5)

Part of the SIEM Foundations domain, which makes up ~34% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~17–27 in this domain), expect 6–9 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)

44questions here
9free pages
6concepts

Questions 21–25

  1. 21foundation · easy

    What is the typical goal of adjusting a correlation rule's threshold (e.g., from 5 failed logins to 10 failed logins within 5 minutes)?

    Select an answer first
  2. 22application · medium

    A detection engineer is building a correlation rule to detect a single user account being used from multiple geographic locations within a short time window. The SIEM receives logs from VPN gateways, Active Directory authentication, and web proxies. Which combination of log sources and correlation logic is most appropriate for this rule?

    Select an answer first
  3. 23application · medium

    A security analyst notices that a single user account has been locked out multiple times in the past hour. The SIEM has authentication logs from domain controllers and a correlation rule that triggers on five or more failed logins within 10 minutes. The analyst wants to determine whether this is a brute-force attack or a user repeatedly mistyping their password. Which additional log source would provide the most useful context for this triage?

    Select an answer first
  4. 24application · medium

    An alert fires for a possible data exfiltration: a user uploaded 2 GB of data to a cloud storage service within 10 minutes. The user is from the marketing department and frequently uploads large files for campaign assets. The analyst checks the user's past activity and sees similar uploads on a weekly basis. What is the most appropriate triage decision?

    Select an answer first
  5. 25foundation · easy

    An analyst receives an alert for a potential malware download. During triage, which action is most appropriate to determine if the alert is a true positive?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCDA” is a trademark of its owner, used for identification only.