Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Enterprise Defender

Domain 1Objective 2

Defensive Infrastructure and Tactics GCED Practice Questions (Page 3)

Part of the Network Defense and Monitoring domain, which makes up ~34% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~24–41 in this domain), expect 6–10 from this objective — we provide 41 practice questions to prepare you well beyond it. (estimate)

41questions here
9free pages
7concepts

Questions 11–15

  1. 11foundation · easy

    Which network traffic pattern is most likely to indicate a port scan?

    Select an answer first
  2. 12application · medium

    A network analyst is reviewing packet captures and notices a series of TCP SYN packets sent to multiple ports on a single host from the same source IP, with no subsequent ACK packets. The analyst wants to confirm whether this is a port scan. Which additional observation would most strongly support that conclusion?

    Select an answer first
  3. 13application · medium

    A security team wants to detect attackers who are already inside the network and moving laterally. They have deployed a honeypot that emulates a file server with fake credentials and sensitive-looking documents. Which additional action would best complement the honeypot to detect lateral movement?

    Select an answer first
  4. 14application · medium

    A security operations center (SOC) receives a threat intelligence feed containing a list of malicious IP addresses and domains. The SOC wants to integrate this feed into their defensive infrastructure to automatically block traffic to these indicators. Which integration approach is most effective and least likely to cause operational disruption?

    Select an answer first
  5. 15application · medium

    A security operations team wants to improve detection of command-and-control (C2) traffic. They have access to a threat intelligence feed that provides domain names and IP addresses associated with known C2 infrastructure. Which integration would provide the most comprehensive detection coverage?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCED” is a trademark of its owner, used for identification only.