Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Defending Advanced Threats

Domain 4Objective 1

Data Exfiltration GDAT Practice Questions (Page 2)

Part of the Exfiltration and Emulation domain, which makes up ~19% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–15 in this domain), expect 5–8 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)

45questions here
9free pages
4concepts

Questions 6–10

  1. 6application · medium

    A security analyst is reviewing firewall logs and sees a workstation making outbound connections to a remote IP address on port 443, but the traffic pattern is unusual: the connections are short-lived and occur every few minutes. The workstation has no business reason to connect to that IP. What should the analyst do first?

    Select an answer first
  2. 7application · medium

    A company has implemented a DLP solution that monitors outbound email and web traffic. However, the security team is concerned about data exfiltration via file-sharing services that use HTTPS. What additional monitoring capability would best address this gap?

    Select an answer first
  3. 8application · medium

    During an incident response, you discover that an attacker has been using HTTPS to a cloud storage service to upload files from a compromised server. The server is still running and the attacker may still have access. What is the most appropriate immediate response step?

    Select an answer first
  4. 9expert · hard

    A security analyst is investigating a potential data exfiltration incident. The network logs show that a large amount of data was transferred to an external IP over a period of several hours. However, the data was encrypted, and the analyst cannot see the content. The analyst also notices that the external IP is associated with a legitimate cloud service used by the company. What is the most appropriate next step?

    Select an answer first
  5. 10expert · hard

    A company is implementing a data exfiltration prevention strategy. They have a mix of on-premises and cloud workloads, and they need to protect data in transit and at rest. They also need to comply with data residency requirements. Which combination of controls would best meet these needs?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GDAT” is a trademark of its owner, used for identification only.