Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Enterprise Defender

Domain 1Objective 3

Intrusion Detection and Packet Analysis GCED Practice Questions (Page 5)

Part of the Network Defense and Monitoring domain, which makes up ~34% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~24–41 in this domain), expect 6–10 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)

40questions here
8free pages
9concepts

Questions 21–25

  1. 21application · medium

    A company needs to monitor for malicious activity on a network segment that carries traffic between application servers and a database. The traffic is encrypted with TLS. The security team wants to detect attacks that exploit application-layer vulnerabilities, but they cannot decrypt the traffic due to compliance constraints. Which approach is most effective?

    Select an answer first
  2. 22application · medium

    A company wants to monitor wireless network traffic for rogue access points and unauthorized client associations. They already have a network-based IDS on the wired segment. What additional deployment is most appropriate?

    Select an answer first
  3. 23expert · hard

    A SOC is overwhelmed by IDS alerts, many of which are false positives caused by legitimate internal scanning tools. The team wants to reduce alert noise without missing real attacks. They have identified the scanning tool's IP addresses and the time windows when scans run. Which approach is most effective?

    Select an answer first
  4. 24expert · hard

    An analyst is correlating IDS alerts and notices that a series of low-severity alerts, when viewed together, indicate a multi-step attack. The individual alerts are: (1) an unusual outbound connection from a workstation, (2) a spike in DNS queries from the same workstation, and (3) a file integrity alert on the same workstation. What is the best way to handle these correlated alerts?

    Select an answer first
  5. 25application · medium

    An analyst is using tcpdump to capture traffic on an interface but is missing packets during high traffic periods. The analyst needs to reduce packet loss. Which action is most effective?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCED” is a trademark of its owner, used for identification only.