
GIAC Certified Detection Analyst
Domain 1Objective 3
Log Analysis and Alerting GCDA Practice Questions (Page 6)
Part of the SIEM Foundations domain, which makes up ~34% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~17–27 in this domain), expect 6–9 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
6concepts
Questions 26–30
- 26
In a SIEM, what does the severity level of an alert typically indicate?
Select an answer first - 27
A SIEM rule alerts when a user creates a new account and then adds it to a privileged group within 1 hour. The rule is producing many false positives because help desk staff routinely create accounts and add them to groups as part of onboarding. The security team wants to reduce noise while still detecting unauthorized privilege escalation. The help desk uses a specific service account for these tasks. Which tuning approach is most effective?
Select an answer first - 28
A SIEM rule alerts on any outbound connection to a known malicious domain. The rule has generated 50 alerts in the past week, but only 2 were confirmed as true positives. The false positives are all from a specific business unit that uses a web filtering service that performs SSL inspection and connects to the domain for categorization checks. What is the best tuning action?
Select an answer first - 29
A correlation rule detects multiple failed logins followed by a successful login from the same source IP. The rule currently sends an email to the security team. The team wants to ensure that high-severity alerts are handled quickly even outside business hours. Which configuration change best addresses this?
Select an answer first - 30
A SIEM correlation rule triggers an alert when a user logs in from a foreign country and then performs a privileged action within 1 hour. The alert is set to severity 'high' and sends an email to the security operations team. The team is missing these alerts because they are buried in a shared inbox. What is the most effective way to ensure these alerts are noticed and acted upon?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCDA” is a trademark of its owner, used for identification only.