
GIAC Certified Enterprise Defender
Domain 1Objective 3
Intrusion Detection and Packet Analysis GCED Practice Questions (Page 8)
Part of the Network Defense and Monitoring domain, which makes up ~34% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~24–41 in this domain), expect 6–10 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)
40questions here
8free pages
9concepts
Questions 36–40
- 36
A security team is evaluating an IDS for a network that frequently sees new, custom applications generating unusual traffic patterns. The team is concerned about zero-day exploits and wants to minimize false positives. Which detection method is most appropriate?
Select an answer first - 37
An IDS generates a high number of alerts for a specific signature. The analyst investigates and finds that the alerts are triggered by a legitimate application that uses a protocol that is similar to the attack pattern. The analyst needs to reduce the false positives while maintaining detection for actual attacks. Which approach is most effective?
Select an answer first - 38
When an IDS generates an alert that indicates a possible security incident, what is the FIRST step in integrating this finding into incident response?
Select an answer first - 39
Which command-line tool is commonly used to capture packets on a Linux interface and display them in real time?
Select an answer first - 40
A security team is choosing an IDS for a network that carries both encrypted and unencrypted traffic. The team needs to detect known malware signatures and also identify protocol anomalies. They are concerned about evasion via encryption. Which detection method is most resilient to encryption-based evasion?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GCED
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCED” is a trademark of its owner, used for identification only.