Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Enterprise Defender

Domain 1Objective 3

Intrusion Detection and Packet Analysis GCED Practice Questions (Page 4)

Part of the Network Defense and Monitoring domain, which makes up ~34% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~24–41 in this domain), expect 6–10 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)

40questions here
8free pages
9concepts

Questions 16–20

  1. 16foundation · easy

    Why is it important to preserve the original packet capture (PCAP) files when responding to an incident detected by an IDS?

    Select an answer first
  2. 17foundation · easy

    In a TCP packet header, which field is used to identify the application or service on the destination host?

    Select an answer first
  3. 18foundation · easy

    Which traffic pattern is most indicative of a network reconnaissance scan?

    Select an answer first
  4. 19application · medium

    A network analyst notices that an IDS is generating alerts for a known exploit signature, but the exploit is not succeeding. The analyst suspects an attacker is using fragmentation to evade detection. Which observation would confirm this suspicion?

    Select an answer first
  5. 20expert · hard

    A security team is comparing IDS detection methods for a network that experiences high false positives with signature-based detection. They also need to detect polymorphic malware that changes its signature. Which detection method is most effective for polymorphic malware?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCED” is a trademark of its owner, used for identification only.