Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Detection Analyst

Domain 1Objective 3

Log Analysis and Alerting GCDA Practice Questions (Page 9)

Part of the SIEM Foundations domain, which makes up ~34% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~17–27 in this domain), expect 6–9 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)

44questions here
9free pages
6concepts

Questions 41–44

  1. 41application · medium

    An analyst is triaging an alert that fired when a user account was created and then immediately added to the Domain Admins group. The alert has a severity of 'high'. During triage, the analyst checks the account creation logs and sees that the account was created by a known administrator account during business hours. What is the most appropriate next step?

    Select an answer first
  2. 42expert · hard

    An analyst is triaging an alert that fired when a user logged in from a new device and then immediately changed their password. The alert severity is 'medium'. The analyst checks the user's manager and finds that the user is on a known business trip. The new device is a company-issued laptop. What is the most appropriate triage decision?

    Select an answer first
  3. 43application · medium

    An analyst is investigating an alert that fired when a user downloaded a file from an external website and then executed it. The alert severity is 'medium'. The analyst checks the file hash against a threat intelligence feed and finds no known malicious indicators. What should the analyst do next?

    Select an answer first
  4. 44expert · hard

    An analyst is triaging an alert for a PowerShell process that made an outbound connection to a known malicious IP. The alert includes the hostname, user, and command line. The analyst checks the host's process creation logs and sees that the PowerShell process was spawned by a legitimate administrative script that is scheduled to run nightly. The script is known to download updates from a vendor CDN, but the IP in the alert is not the vendor's CDN. What is the most appropriate triage action?

    Select an answer first
Finished these 4 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to GCDA

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCDA” is a trademark of its owner, used for identification only.