
GIAC Certified Enterprise Defender
Domain 1Objective 4
Network Security Monitoring Concepts and Application GCED Practice Questions (Page 5)
Part of the Network Defense and Monitoring domain, which makes up ~34% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~24–41 in this domain), expect 6–10 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
8concepts
Questions 21–25
- 21
In an NSM workflow, what typically happens after a security alert is generated?
Select an answer first - 22
An incident responder needs to determine whether a malware sample exfiltrated data over HTTP POST requests. Which NSM data source would provide the most definitive evidence of the content that was sent?
Select an answer first - 23
What is the first step in a typical NSM workflow?
Select an answer first - 24
What is a key resource consideration when deploying a full packet capture solution?
Select an answer first - 25
A company's network monitoring team is unable to inspect the contents of HTTPS traffic to detect malicious payloads. They are considering deploying a TLS interception proxy. What is the most important prerequisite for this approach to work effectively?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCED” is a trademark of its owner, used for identification only.