
GIAC Certified Enterprise Defender
Domain 2Objective 3
Network Forensics, Logging, and Event Management GCED Practice Questions (Page 9)
Part of the Incident Response and Forensics domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–35 in this domain), expect 7–12 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
8concepts
Questions 41–42
- 41
A security analyst is investigating a potential lateral movement. The SIEM shows a user logging into a server at 10:00 AM, followed by a series of administrative commands. The analyst also sees a separate event of the same user logging into another server at 10:05 AM. What should the analyst do to confirm lateral movement?
Select an answer first - 42
A forensic investigator is collecting network traffic logs as evidence for a legal case. The investigator needs to ensure the evidence is admissible in court. Which action is most important to maintain the chain of custody?
Select an answer first
Finished these 2 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GCED
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCED” is a trademark of its owner, used for identification only.