
GIAC Certified Enterprise Defender
Domain 2Objective 3
Network Forensics, Logging, and Event Management GCED Practice Questions (Page 5)
Part of the Incident Response and Forensics domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–35 in this domain), expect 7–12 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
8concepts
Questions 21–25
- 21
A company is required to retain logs for two years for compliance. They currently store logs in a SIEM with a one-year retention period. The SIEM is nearing capacity, and extending retention would require significant additional storage investment. The company is considering archiving older logs to a low-cost storage solution. Which of the following is the most important consideration when implementing this archive?
Select an answer first - 22
A company is deploying a SIEM and wants to ensure that alerts are actionable and not overwhelming. Which of the following is the most effective practice to achieve this?
Select an answer first - 23
A company is investigating a data breach that occurred over a month ago. The security team has firewall logs, but they did not capture full packet data. The legal team is asking for evidence that can be used in court. What is the best course of action?
Select an answer first - 24
An analyst is reviewing logs from multiple sources during an incident. The firewall logs show a connection from an internal IP to an external IP on port 443. The IDS logs show a signature match for 'malicious SSL traffic' for the same connection. The Windows event logs on the internal host show a process that made an outbound connection to that external IP. Which of the following is the most complete and accurate conclusion?
Select an answer first - 25
A security analyst is investigating a potential brute-force attack. The SIEM shows multiple failed login attempts from a single IP address against the VPN gateway, followed by a successful login from the same IP. However, the analyst also sees that the same IP address has been used for successful logins in the past. What should the analyst do next?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCED” is a trademark of its owner, used for identification only.