
GIAC Certified Enterprise Defender
Domain 2Objective 3
Network Forensics, Logging, and Event Management GCED Practice Questions (Page 7)
Part of the Incident Response and Forensics domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–35 in this domain), expect 7–12 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
8concepts
Questions 31–35
- 31
A security analyst is investigating a potential data exfiltration. The SIEM shows a large amount of data being transferred from an internal server to an external IP address via FTP. The analyst also sees that the same external IP was used in a previous incident. However, the FTP traffic is not encrypted. What is the best way to confirm the exfiltration?
Select an answer first - 32
Which tool provides a graphical interface for capturing and analyzing network packets?
Select an answer first - 33
An analyst is reviewing logs from multiple sources and notices that the timestamps are in different formats. The firewall logs use UTC, the web server logs use local time, and the IDS logs use epoch time. The analyst needs to correlate events across these sources. What is the best approach?
Select an answer first - 34
In network traffic analysis, what does a sudden spike in outbound traffic from a single host to an external IP often indicate?
Select an answer first - 35
Which activity is a core function of network forensics during incident response?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCED” is a trademark of its owner, used for identification only.