Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Enterprise Defender

Domain 1Objective 2

Defensive Infrastructure and Tactics GCED Practice Questions (Page 8)

Part of the Network Defense and Monitoring domain, which makes up ~34% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~24–41 in this domain), expect 6–10 from this objective — we provide 41 practice questions to prepare you well beyond it. (estimate)

41questions here
9free pages
7concepts

Questions 36–40

  1. 36application · medium

    A company's intrusion detection system (IDS) alerts on suspicious outbound traffic from a finance department workstation to an external IP. The workstation user is currently logged in and working. The incident response team needs to contain the potential compromise while minimizing business disruption. Which action is the most appropriate initial containment step?

    Select an answer first
  2. 37application · medium

    A company is deploying a new remote access solution for its employees. The employees will work from home and need to access internal applications. The security team wants to ensure that all remote access traffic is encrypted and that only authorized employees can connect. Which defensive infrastructure component is most appropriate for this requirement?

    Select an answer first
  3. 38expert · hard

    A security architect is designing a defense-in-depth strategy for a large enterprise. The enterprise has a mature security operations center (SOC) and a threat intelligence team. The architect wants to implement a deception layer to detect attackers who have bypassed other controls. Which approach is most effective for this purpose?

    Select an answer first
  4. 39foundation · easy

    What is the primary purpose of placing publicly accessible servers in a DMZ?

    Select an answer first
  5. 40expert · hard

    A security team is deploying a honeynet to detect and analyze attacker behavior. The honeynet consists of several honeypots that emulate different services. The team wants to ensure that the honeynet does not become a launching point for attacks against production systems. Which control is most important to prevent this?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCED” is a trademark of its owner, used for identification only.