
GIAC Certified Enterprise Defender
Domain 1Objective 3
Intrusion Detection and Packet Analysis GCED Practice Questions (Page 3)
Part of the Network Defense and Monitoring domain, which makes up ~34% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~24–41 in this domain), expect 6–10 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)
40questions here
8free pages
9concepts
Questions 11–15
- 11
A small company has a flat network with no segmentation. They want to deploy an IDS to monitor for malicious activity but have a limited budget and no dedicated security staff. Which deployment is most practical?
Select an answer first - 12
An attacker is using an IDS evasion technique that involves sending the same payload in overlapping IP fragments, where the second fragment overwrites part of the first. The IDS reassembles fragments differently than the target host. What is the primary goal of this technique?
Select an answer first - 13
What is the primary purpose of an intrusion detection system (IDS) in a network defense strategy?
Select an answer first - 14
A security analyst is examining a packet capture and sees a TCP connection with the SYN flag set, followed by a RST flag from the destination, and then a new SYN to the same destination. This pattern repeats for multiple destination ports. What does this pattern most likely indicate?
Select an answer first - 15
Which detection method is most effective at identifying previously unknown attacks that do not match any known signature?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCED” is a trademark of its owner, used for identification only.