
GIAC Certified Enterprise Defender
Domain 1Objective 3
Intrusion Detection and Packet Analysis GCED Practice Questions (Page 7)
Part of the Network Defense and Monitoring domain, which makes up ~34% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~24–41 in this domain), expect 6–10 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)
40questions here
8free pages
9concepts
Questions 31–35
- 31
A security analyst is investigating a report of a compromised workstation. The analyst captures traffic on the workstation's network segment and observes a large volume of TCP SYN packets sent to a single external IP address across a wide range of destination ports, with no corresponding SYN-ACK replies. The analyst also notices that the workstation is sending a steady stream of small UDP packets to the same external IP address. Which conclusion is best supported by this traffic pattern?
Select an answer first - 32
A security team is evaluating IDS detection methods for a network that experiences frequent false positives from signature-based alerts. The team needs to reduce false positives while still detecting known attacks and novel variants. They have a large dataset of normal traffic and a smaller dataset of known attack traffic. Which approach best balances these requirements?
Select an answer first - 33
Which technique is commonly used by attackers to evade signature-based IDS by splitting malicious payloads across multiple small packets?
Select an answer first - 34
A SOC analyst is reviewing a burst of IDS alerts from the perimeter. The alerts include: (1) multiple ICMP echo requests from 198.51.100.7 to various internal hosts, (2) TCP SYN packets from the same IP to port 22 on several internal servers, and (3) a successful SSH login from 198.51.100.7 to a jump host. The analyst must decide whether these are separate incidents or one coordinated attack. Which action best applies alert correlation to this situation?
Select an answer first - 35
Which type of intrusion detection system is best suited to monitor traffic crossing a network segment between two internal subnets?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCED” is a trademark of its owner, used for identification only.