
GIAC Certified Enterprise Defender
Domain 2Objective 3
Network Forensics, Logging, and Event Management GCED Practice Questions (Page 2)
Part of the Incident Response and Forensics domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–35 in this domain), expect 7–12 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
8concepts
Questions 6–10
- 6
An incident responder needs to capture traffic on a high-availability production network. The network uses link aggregation (LACP) between switches and servers. The responder has access to the switches and can configure SPAN. However, SPAN ports do not capture traffic on all members of an LACP bundle by default. Which of the following is the most effective approach to capture all traffic?
Select an answer first - 7
An analyst is investigating an incident and needs to correlate events from a firewall, an IDS, and a Windows server. The logs are in different formats and have different timestamps. Which of the following is the most important step to enable effective correlation?
Select an answer first - 8
A forensic investigator has captured network traffic and needs to present the evidence in court. The defense attorney challenges the authenticity of the capture, claiming it may have been altered. Which of the following is the most effective way to rebut this challenge?
Select an answer first - 9
A company's security team is implementing a centralized logging solution. They need to ensure that logs from firewalls, IDS, and Windows servers are collected and retained for at least one year to meet compliance requirements. They also want to be able to search logs quickly during investigations. Which approach best meets these needs?
Select an answer first - 10
Which type of network traffic pattern is commonly associated with a port scan?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCED” is a trademark of its owner, used for identification only.