
GIAC Certified Enterprise Defender
Domain 1Objective 2
Defensive Infrastructure and Tactics GCED Practice Questions (Page 6)
Part of the Network Defense and Monitoring domain, which makes up ~34% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~24–41 in this domain), expect 6–10 from this objective — we provide 41 practice questions to prepare you well beyond it. (estimate)
41questions here
9free pages
7concepts
Questions 26–30
- 26
A company is recovering from a ransomware attack that affected multiple servers in the same subnet. The incident response team has identified the initial entry point and is ready to restore systems. The company wants to prevent a recurrence and improve future response. Which set of actions is most comprehensive?
Select an answer first - 27
What is the primary goal of the containment phase in incident response?
Select an answer first - 28
What does a sudden spike in outbound DNS queries from an internal host often indicate?
Select an answer first - 29
A company has experienced a ransomware attack that encrypted files on several file servers. The incident response team has identified the initial entry point as a phishing email with a malicious attachment. The team has contained the spread by isolating the affected servers. What is the next step in the incident response process?
Select an answer first - 30
What is the primary role of an intrusion prevention system (IPS) in a network defense architecture?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCED” is a trademark of its owner, used for identification only.