Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Detection Analyst

Domain 1Objective 2

Log Collection and Enrichment GCDA Practice Questions (Page 8)

Part of the SIEM Foundations domain, which makes up ~34% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~17–27 in this domain), expect 6–9 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)

44questions here
9free pages
6concepts

Questions 36–40

  1. 36expert · hard

    A company has a remote office with a low-bandwidth link. The SIEM is centralized at headquarters. The remote firewall generates high-volume logs, and the link is congested. The security team wants to ensure logs are collected without overwhelming the link. What is the best approach?

    Select an answer first
  2. 37application · medium

    A security team needs to collect logs from a cloud SaaS application that does not support syslog or agent installation. The application provides a REST API that returns JSON events for the last 24 hours. The team wants to ingest these logs into the SIEM with minimal infrastructure. Which collection method should they use?

    Select an answer first
  3. 38expert · hard

    A SIEM engineer is designing enrichment for authentication logs. The company has a strict data residency requirement: all personal data must remain in the EU. The threat intelligence feed is hosted in the US and requires sending IP addresses for lookup. How should the engineer handle enrichment to comply with the requirement?

    Select an answer first
  4. 39foundation · medium

    A security analyst is configuring a SIEM to collect logs from a Windows domain controller. Which log source and type combination is most appropriate for collecting authentication events?

    Select an answer first
  5. 40application · medium

    A detection engineer is integrating a new firewall that sends logs in a proprietary key=value format. The SIEM's default parser does not recognize the field names, so events arrive with the raw message stored in a single field. The team needs to search for source and destination IPs in a consistent way across all firewall vendors. What should the engineer do first?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCDA” is a trademark of its owner, used for identification only.