
GIAC Certified Detection Analyst
Domain 1Objective 2
Log Collection and Enrichment GCDA Practice Questions (Page 9)
Part of the SIEM Foundations domain, which makes up ~34% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~17–27 in this domain), expect 6–9 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
6concepts
Questions 41–44
- 41
Which external data source is commonly used to enrich logs with the geographic location of an IP address?
Select an answer first - 42
A security analyst is reviewing firewall logs and sees an outbound connection to an IP address in a foreign country. The analyst wants to determine if this IP is associated with known malicious activity and whether the asset is a critical server. Which enrichment sources should be used?
Select an answer first - 43
A security team must collect logs from a legacy industrial control system (ICS) that only supports syslog over UDP. The SIEM is on a different network segment, and the team is concerned about log loss and spoofing. They also need to maintain a forensic chain of custody. Which approach best addresses these concerns?
Select an answer first - 44
A cloud-based SaaS application only exposes an API for retrieving audit logs. The security team needs to ingest these logs into the SIEM on a continuous basis. Which collection method is most appropriate?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GCDA
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCDA” is a trademark of its owner, used for identification only.