Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Defending Advanced Threats

Domain 5Objective 1

Reconnaissance, Threat Handling, and Incident Response GDAT Practice Questions (Page 10)

Part of the Defense and Response domain, which makes up ~13% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~7–10 in this domain), expect 7–10 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)

53questions here
11free pages
9concepts

Questions 46–50

  1. 46application · medium

    An analyst detects a suspicious process on a server that is communicating with an external IP address. The analyst has isolated the server and collected memory and disk images. What is the next step in the threat handling process?

    Select an answer first
  2. 47expert · hard

    A threat intelligence platform provides two feeds: one with high-confidence indicators of compromise (IOCs) for a specific APT group, and another with low-confidence indicators from a broader set of sources. The security team has limited resources and must prioritize detection efforts. What is the most effective approach?

    Select an answer first
  3. 48expert · hard

    A post-incident review identifies that the incident response team lacked visibility into cloud-based assets, which delayed detection. The team also found that threat intelligence was not integrated into the SIEM. What is the most effective improvement to implement?

    Select an answer first
  4. 49application · medium

    A security analyst is reviewing a suspicious process that is making outbound connections to an IP address that is not on any blocklist. The process name is 'svchost.exe' but it is running from the user's Temp directory. Which indicator of compromise is most reliable in confirming malicious activity?

    Select an answer first
  5. 50expert · hard

    A security team is investigating a series of alerts that appear to be related to a known advanced persistent threat (APT) group. The team has access to threat intelligence that includes the group's tactics, techniques, and procedures (TTPs). How should the team use this intelligence to improve its incident response?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GDAT” is a trademark of its owner, used for identification only.