Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Enterprise Defender

Domain 2Objective 3

Network Forensics, Logging, and Event Management GCED Practice Questions (Page 9)

Part of the Incident Response and Forensics domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–35 in this domain), expect 7–12 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)

42questions here
9free pages
8concepts

Questions 41–42

  1. 41application · medium

    A security analyst is investigating a potential lateral movement. The SIEM shows a user logging into a server at 10:00 AM, followed by a series of administrative commands. The analyst also sees a separate event of the same user logging into another server at 10:05 AM. What should the analyst do to confirm lateral movement?

    Select an answer first
  2. 42application · medium

    A forensic investigator is collecting network traffic logs as evidence for a legal case. The investigator needs to ensure the evidence is admissible in court. Which action is most important to maintain the chain of custody?

    Select an answer first
Finished these 2 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to GCED

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCED” is a trademark of its owner, used for identification only.