
GIAC Certified Detection Analyst
Domain 1Objective 2
Log Collection and Enrichment GCDA Practice Questions (Page 7)
Part of the SIEM Foundations domain, which makes up ~34% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~17–27 in this domain), expect 6–9 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
6concepts
Questions 31–35
- 31
A network engineer wants to collect logs from a Cisco router. Which log source and type is most commonly used for this device?
Select an answer first - 32
An organization needs to collect logs from a cloud-based SaaS application that does not support syslog or agent installation. Which log collection method is most appropriate?
Select an answer first - 33
A company wants to collect logs from its network firewall, web server, and database. The firewall supports syslog, the web server writes JSON logs to a file, and the database has an audit log that can be queried via SQL. Which combination of collection methods should the team use?
Select an answer first - 34
An organization wants to enrich authentication logs with the department and manager of each user. Which enrichment data source should be integrated?
Select an answer first - 35
A SIEM is receiving logs from a network sensor that sends events with a monotonically increasing sequence number. Analysts suspect that some events are missing. How can the SIEM detect missing events?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCDA” is a trademark of its owner, used for identification only.