
GIAC Certified Detection Analyst
Domain 1Objective 3
Log Analysis and Alerting GCDA Practice Questions (Page 7)
Part of the SIEM Foundations domain, which makes up ~34% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~17–27 in this domain), expect 6–9 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
6concepts
Questions 31–35
- 31
A detection engineer wants to create a rule that detects a potential brute-force attack on a web application. The rule should trigger when a single source IP sends many HTTP 401 responses to the web server. Which log source and field combination is most appropriate?
Select an answer first - 32
A security analyst is reviewing logs from a web server, a firewall, and a Linux host. Which statement correctly describes a common characteristic of these log sources?
Select an answer first - 33
A SOC team has a correlation rule that triggers an alert whenever a user fails to authenticate 5 times within 10 minutes. The alert severity is set to 'high' and it pages the on-call analyst. Recently, the team has been overwhelmed by alerts from a legacy application that uses a service account which retries authentication every minute. What is the most effective immediate action to reduce noise while preserving detection of actual brute-force attacks?
Select an answer first - 34
A SIEM rule alerts on any process that creates a scheduled task. The rule has a high false-positive rate because many legitimate software updates create scheduled tasks. The SOC wants to reduce noise while still detecting malicious scheduled task creation. Which tuning approach is most effective?
Select an answer first - 35
A SIEM correlation rule is designed to detect port scanning by alerting when one source IP connects to more than 100 distinct destination ports on a single host within 5 minutes. The security team is overwhelmed by alerts from a vulnerability scanner that runs weekly. The analyst wants to reduce false positives without losing detection of real scans. Which tuning change is most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCDA” is a trademark of its owner, used for identification only.