Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Enterprise Defender

Domain 1Objective 3

Intrusion Detection and Packet Analysis GCED Practice Questions (Page 7)

Part of the Network Defense and Monitoring domain, which makes up ~34% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~24–41 in this domain), expect 6–10 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)

40questions here
8free pages
9concepts

Questions 31–35

  1. 31application · medium

    A security analyst is investigating a report of a compromised workstation. The analyst captures traffic on the workstation's network segment and observes a large volume of TCP SYN packets sent to a single external IP address across a wide range of destination ports, with no corresponding SYN-ACK replies. The analyst also notices that the workstation is sending a steady stream of small UDP packets to the same external IP address. Which conclusion is best supported by this traffic pattern?

    Select an answer first
  2. 32expert · hard

    A security team is evaluating IDS detection methods for a network that experiences frequent false positives from signature-based alerts. The team needs to reduce false positives while still detecting known attacks and novel variants. They have a large dataset of normal traffic and a smaller dataset of known attack traffic. Which approach best balances these requirements?

    Select an answer first
  3. 33foundation · easy

    Which technique is commonly used by attackers to evade signature-based IDS by splitting malicious payloads across multiple small packets?

    Select an answer first
  4. 34expert · hard

    A SOC analyst is reviewing a burst of IDS alerts from the perimeter. The alerts include: (1) multiple ICMP echo requests from 198.51.100.7 to various internal hosts, (2) TCP SYN packets from the same IP to port 22 on several internal servers, and (3) a successful SSH login from 198.51.100.7 to a jump host. The analyst must decide whether these are separate incidents or one coordinated attack. Which action best applies alert correlation to this situation?

    Select an answer first
  5. 35foundation · easy

    Which type of intrusion detection system is best suited to monitor traffic crossing a network segment between two internal subnets?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCED” is a trademark of its owner, used for identification only.