
GIAC Certified Detection Analyst
Domain 1Objective 1
SIEM Overview GCDA Practice Questions (Page 7)
Part of the SIEM Foundations domain, which makes up ~34% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~17–27 in this domain), expect 6–9 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)
47questions here
10free pages
8concepts
Questions 31–35
- 31
A company is considering implementing a SIEM to improve its security posture. The security team has identified that they need to detect a specific attack pattern that involves multiple steps across different systems. They also need to ensure that the SIEM can handle the volume of logs from their environment. What is the most important factor to consider when evaluating SIEM solutions?
Select an answer first - 32
How do correlation rules map to use cases?
Select an answer first - 33
A SIEM analyst is writing a correlation rule that needs to match events from a firewall and a Windows server. The firewall logs use 'src_ip' for the source address, while the Windows logs use 'Source_IP'. The rule is not matching events as expected. What is the most likely reason?
Select an answer first - 34
A SIEM is receiving logs from a firewall and an antivirus product. The firewall logs use 'src_ip' and the antivirus logs use 'source_address' for the same concept. An analyst wants to write a single correlation rule that checks the source IP across both sources. What must be done first?
Select an answer first - 35
Which of the following is a core function of a SIEM?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCDA” is a trademark of its owner, used for identification only.