
GIAC Certified Detection Analyst
Domain 1Objective 3
Log Analysis and Alerting GCDA Practice Questions (Page 8)
Part of the SIEM Foundations domain, which makes up ~34% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~17–27 in this domain), expect 6–9 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
6concepts
Questions 36–40
- 36
A security team wants to detect a potential data exfiltration scenario where a user downloads a large file from an internal server and then uploads it to an external cloud storage service. The SIEM has logs from the internal file server, the web proxy, and the firewall. The team wants to create a correlation rule that minimizes false positives. Which rule logic is most effective?
Select an answer first - 37
A detection engineer is building a correlation rule to identify data exfiltration via DNS. The rule needs to detect when a client sends a large number of DNS queries for unique subdomains under a single domain. Which log source is most appropriate for this rule?
Select an answer first - 38
An organization wants to ensure that critical security alerts are seen by on-call staff even outside business hours. Which alerting mechanism is most appropriate?
Select an answer first - 39
A SOC has a rule that generates an alert for any successful login outside business hours. The alert is configured with severity 'medium' and sends an email to the SOC mailbox. The team has noticed that many alerts are for legitimate remote workers in different time zones. What is the most appropriate adjustment to the alerting configuration?
Select an answer first - 40
A company is ingesting logs from multiple sources, including Windows Event Logs, Linux syslog, and custom application logs. The SIEM normalizes all logs into a common schema. A correlation rule is written to detect a user who logs in from a new device. The rule uses the 'user' and 'device' fields. Which normalization step is essential for this rule to work correctly across all log sources?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCDA” is a trademark of its owner, used for identification only.