
GIAC Certified Detection Analyst
Domain 1Objective 2
Log Collection and Enrichment GCDA Practice Questions (Page 5)
Part of the SIEM Foundations domain, which makes up ~34% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~17–27 in this domain), expect 6–9 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
6concepts
Questions 21–25
- 21
What is a common method to ensure the integrity of logs during collection and transmission?
Select an answer first - 22
Why is it important to ensure consistent timestamp formats in collected logs?
Select an answer first - 23
A SIEM is receiving logs from a load balancer that occasionally drops events during peak traffic. Analysts notice gaps in the data. What is the most effective way to detect and address this issue?
Select an answer first - 24
A SIEM receives authentication logs from multiple domain controllers. Analysts want to quickly identify which events involve privileged accounts. What enrichment technique should be applied during ingestion?
Select an answer first - 25
A security team wants to automatically add the business owner of each asset to the logs generated by that asset. Which enrichment technique should be used?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCDA” is a trademark of its owner, used for identification only.