Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Enterprise Defender

Domain 2Objective 3

Network Forensics, Logging, and Event Management GCED Practice Questions (Page 4)

Part of the Incident Response and Forensics domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–35 in this domain), expect 7–12 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)

42questions here
9free pages
8concepts

Questions 16–20

  1. 16foundation · easy

    Which component of a SIEM is responsible for collecting logs from various sources?

    Select an answer first
  2. 17foundation · easy

    Which scenario best illustrates event correlation?

    Select an answer first
  3. 18foundation · easy

    Which action is essential when collecting network forensic evidence to maintain chain of custody?

    Select an answer first
  4. 19application · medium

    A security team is designing a log management strategy. They need to ensure that logs are available for incident investigation even if the original source system is compromised or destroyed. Which of the following is the most important control to implement?

    Select an answer first
  5. 20expert · hard

    An incident responder needs to capture network traffic on a high-traffic production server. The server has limited disk space, and the capture must not interfere with performance. The responder needs to capture traffic for a specific IP address and save it for later analysis. Which approach best balances performance and storage?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCED” is a trademark of its owner, used for identification only.