Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Detection Analyst

Domain 1Objective 1

SIEM Overview GCDA Practice Questions (Page 2)

Part of the SIEM Foundations domain, which makes up ~34% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~17–27 in this domain), expect 6–9 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)

47questions here
10free pages
8concepts

Questions 6–10

  1. 6foundation · easy

    Which of the following is a common data source for a SIEM?

    Select an answer first
  2. 7expert · hard

    A SOC is experiencing a high volume of low-priority alerts, causing analysts to miss critical alerts. They want to reduce noise without losing important detections. Which approach best balances noise reduction and detection coverage?

    Select an answer first
  3. 8foundation · easy

    Which of the following is a common type of SIEM report used for security posture monitoring?

    Select an answer first
  4. 9expert · hard

    An organization must provide auditors with evidence that security monitoring is effective. They currently have a SIEM but do not have a formal reporting process. Which approach best demonstrates monitoring effectiveness to auditors?

    Select an answer first
  5. 10application · medium

    A security operations center (SOC) is being overwhelmed by a high volume of low-priority alerts from a SIEM. The team wants to reduce noise while ensuring that critical alerts are still escalated to the incident response team. What is the most effective approach?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCDA” is a trademark of its owner, used for identification only.