Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Cloud Threat Detection

Domain 3Objective 1

Automated Detection and Response GCTD Practice Questions (Page 2)

Part of the Cloud Threat Detection and Response domain, which makes up ~25% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 4–7 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)

43questions here
9free pages
10concepts

Questions 6–10

  1. 6foundation · easy

    Which step is part of ingesting cloud logs into a centralized detection platform?

    Select an answer first
  2. 7foundation · easy

    What is the role of a SOAR platform in incident response?

    Select an answer first
  3. 8expert · hard

    A security team has deployed a new detection rule that flags unusual outbound network connections. During the first week, the rule generated 500 alerts, but only 10 were confirmed as malicious. The team wants to improve the rule's precision without significantly reducing its recall. Which approach is most effective?

    Select an answer first
  4. 9foundation · easy

    What is a key benefit of integrating detection systems with a SOAR platform?

    Select an answer first
  5. 10expert · hard

    A security team has a detection rule that generates a high number of false positives, causing alert fatigue. They have tried tuning the rule by adjusting thresholds, but false positives remain high. They need a more effective approach without losing true positives. Which strategy is best?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCTD” is a trademark of its owner, used for identification only.