
GIAC Certified Enterprise Defender
Domain 2Objective 3
Network Forensics, Logging, and Event Management GCED Practice Questions (Page 8)
Part of the Incident Response and Forensics domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–35 in this domain), expect 7–12 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
8concepts
Questions 36–40
- 36
What is the primary purpose of a log retention policy?
Select an answer first - 37
A security team is configuring a SIEM and wants to reduce false positives. They have a rule that alerts on any failed login followed by a successful login. The rule is generating many alerts for legitimate users who mistype their passwords. What is the best way to reduce false positives?
Select an answer first - 38
What is the goal of event correlation in security monitoring?
Select an answer first - 39
An analyst is examining logs from multiple sources to investigate a security incident. The analyst notices that the firewall logs show timestamps in UTC, the web server logs show timestamps in local time, and the IDS logs show timestamps in epoch format. What is the best practice for handling these different timestamp formats?
Select an answer first - 40
An analyst is reviewing logs from a firewall and notices that the log format includes fields for source IP, destination IP, source port, destination port, and action. The analyst needs to correlate these logs with IDS alerts. What is the most important field to use for correlation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCED” is a trademark of its owner, used for identification only.