
GIAC Certified Enterprise Defender
Domain 1Objective 4
Network Security Monitoring Concepts and Application GCED Practice Questions (Page 8)
Part of the Network Defense and Monitoring domain, which makes up ~34% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~24–41 in this domain), expect 6–10 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
8concepts
Questions 36–40
- 36
Which NSM analysis technique relies on predefined patterns or signatures to detect known threats?
Select an answer first - 37
What is the primary function of a Security Information and Event Management (SIEM) system?
Select an answer first - 38
Which technique is used to collect flow-level data from network devices for NSM?
Select an answer first - 39
A small security team is overwhelmed by the volume of alerts from their IDS. They need a solution that can centralize logs from multiple sources, correlate events, and provide a single dashboard for alert triage. Which technology should they implement?
Select an answer first - 40
A security operations center (SOC) is overwhelmed by thousands of daily alerts from multiple IDS sensors and firewalls. Analysts spend most of their time triaging false positives. Which tool or technology should the SOC implement to reduce alert fatigue and improve investigation efficiency?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCED” is a trademark of its owner, used for identification only.