
GIAC Certified Enterprise Defender
Domain 1Objective 3
Intrusion Detection and Packet Analysis GCED Practice Questions (Page 6)
Part of the Network Defense and Monitoring domain, which makes up ~34% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~24–41 in this domain), expect 6–10 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)
40questions here
8free pages
9concepts
Questions 26–30
- 26
Which protocol is connection-oriented and provides reliable, ordered delivery of data?
Select an answer first - 27
During an incident response, an analyst needs to preserve evidence from a compromised server. The analyst has captured network traffic and collected system logs. What is the most important next step to ensure the evidence is admissible in court?
Select an answer first - 28
Why can encryption make intrusion detection more difficult?
Select an answer first - 29
Where is a network-based IDS (NIDS) typically placed to monitor traffic entering an organization's network from the internet?
Select an answer first - 30
Which network traffic behavior is commonly associated with data exfiltration?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCED” is a trademark of its owner, used for identification only.