
GIAC Certified Enterprise Defender
Domain 1Objective 4
Network Security Monitoring Concepts and Application GCED Practice Questions (Page 7)
Part of the Network Defense and Monitoring domain, which makes up ~34% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~24–41 in this domain), expect 6–10 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
8concepts
Questions 31–35
- 31
An organization is implementing NSM for the first time. The security team has limited resources and needs to prioritize which data sources to collect. The primary goal is to detect lateral movement and data exfiltration. Which data source should be prioritized?
Select an answer first - 32
A security analyst needs to investigate a suspected data exfiltration that occurred over a period of several hours. The organization's NSM platform currently stores only NetFlow records and firewall logs. The analyst needs to reconstruct the actual payload of the suspicious HTTPS sessions. What is the most practical limitation the analyst will face with the current data sources?
Select an answer first - 33
An analyst is reviewing NSM data and notices a workstation making repeated connections to an internal file server at odd hours, transferring large amounts of data. The workstation's user is on vacation. Which combination of NSM data sources would best confirm whether this is a compromised account or a misconfigured backup job?
Select an answer first - 34
An organization is experiencing a high rate of false positives from its network IDS, causing analyst fatigue. The IDS is placed on the internal network segment and is seeing legitimate internal application traffic that triggers signatures. Which mitigation strategy would be most effective?
Select an answer first - 35
An organization is evaluating NSM tools. They have a mix of on-premises and cloud infrastructure. The security team wants a single tool that can collect logs from cloud services, on-premises servers, and network devices, and provide real-time alerting. Which tool category best fits this requirement?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCED” is a trademark of its owner, used for identification only.