
GIAC Certified Enterprise Defender
Domain 2Objective 3
Network Forensics, Logging, and Event Management GCED Practice Questions (Page 6)
Part of the Incident Response and Forensics domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–35 in this domain), expect 7–12 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
8concepts
Questions 26–30
- 26
An analyst is reviewing a packet capture from a compromised host. The capture shows a series of TCP connections from the host to an external IP address on port 445, each lasting only a few seconds and transferring small amounts of data. The analyst also notices that the destination IP is not in any threat intelligence feeds. What is the most likely explanation for this traffic pattern?
Select an answer first - 27
An organization's SIEM generates an alert for a single failed login on a domain controller. The security team is overwhelmed with such alerts and wants to reduce false positives while still detecting brute-force attacks. Which of the following is the most effective way to achieve this?
Select an answer first - 28
A company is deploying a SIEM and has a limited budget. They need to decide between two options: a commercial SIEM with advanced correlation and a low-cost open-source SIEM. The company has a small security team with limited expertise. Which of the following is the most important factor in the decision?
Select an answer first - 29
What is the primary purpose of maintaining a chain of custody for digital evidence?
Select an answer first - 30
An analyst is investigating a malware infection and has a packet capture. The capture shows the infected host making HTTP requests to a known malicious domain, but the requests are encrypted with TLS. The analyst also has proxy logs that show the full URL of the requests. Which source provides the most useful information for identifying the malware's C2 behavior?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCED” is a trademark of its owner, used for identification only.