
GIAC Certified Enterprise Defender
Domain 1Objective 1
Defending Network Protocols GCED Practice Questions (Page 5)
Part of the Network Defense and Monitoring domain, which makes up ~34% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~24–41 in this domain), expect 6–10 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)
43questions here
9free pages
5concepts
Questions 21–25
- 21
A network defender is configuring a firewall to block common protocol-based attacks. Which set of rules would most effectively mitigate DNS amplification attacks originating from the internal network?
Select an answer first - 22
During a packet capture analysis, a defender notices that a client is sending DNS queries for a domain, but the responses are coming from an IP address that is not the configured DNS server. The response contains a different IP address for the domain than the one returned by the legitimate DNS server. Which protocol vulnerability is being exploited?
Select an answer first - 23
An analyst notices that a host is sending ICMP packets with a payload larger than the maximum allowed size, causing the receiving system to crash. Which type of attack is this?
Select an answer first - 24
An analyst is using Wireshark to inspect traffic and notices that a client is sending DNS queries to an external server, but the responses are coming from a different IP address. Which type of attack is likely occurring?
Select an answer first - 25
To protect DNS queries from eavesdropping and tampering, which protocol should be implemented?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCED” is a trademark of its owner, used for identification only.