Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Detection Analyst

Domain 1Objective 1

SIEM Overview GCDA Practice Questions (Page 8)

Part of the SIEM Foundations domain, which makes up ~34% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~17–27 in this domain), expect 6–9 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)

47questions here
10free pages
8concepts

Questions 36–40

  1. 36application · medium

    A company has a mix of network devices, servers, and cloud applications. The SIEM team needs to collect logs from all these sources. Some sources support syslog, some have APIs, and some require an agent. What is the most efficient way to manage this heterogeneous collection environment?

    Select an answer first
  2. 37foundation · easy

    Which SIEM component is responsible for analyzing normalized events to identify patterns and potential security incidents?

    Select an answer first
  3. 38expert · hard

    A company has a mix of legacy on-premises systems that only support syslog and modern cloud services that provide API-based log export. The SIEM must collect from both, but the legacy systems cannot be modified. What is the most effective collection strategy?

    Select an answer first
  4. 39foundation · easy

    How do SIEM alerts typically integrate with incident response workflows?

    Select an answer first
  5. 40foundation · easy

    What is the primary purpose of a correlation rule in a SIEM?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCDA” is a trademark of its owner, used for identification only.