
GIAC Certified Enterprise Defender
Domain 1Objective 4
Network Security Monitoring Concepts and Application GCED Practice Questions (Page 3)
Part of the Network Defense and Monitoring domain, which makes up ~34% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~24–41 in this domain), expect 6–10 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
8concepts
Questions 11–15
- 11
What is a key characteristic of anomaly-based detection in NSM?
Select an answer first - 12
Which activity is a core function of Network Security Monitoring?
Select an answer first - 13
An analyst is investigating a potential data breach. The NSM data shows a large outbound transfer from a database server to an external IP. The transfer occurred over a 30-minute period. The analyst has full packet capture, NetFlow, and server logs. Which combination of data sources would provide the most conclusive evidence of data exfiltration?
Select an answer first - 14
Which NSM data source provides the most detailed information about the contents of a network conversation?
Select an answer first - 15
A security team is monitoring a network segment that carries encrypted traffic using TLS. The team wants to detect malicious activity within the encrypted sessions without decrypting the traffic. Which approach is most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCED” is a trademark of its owner, used for identification only.