
GIAC Network Forensic Analyst
Domain 3Objective 2
Security Event and Incident Logging GNFA Practice Questions (Page 1)
Part of the Security Controls and Monitoring domain, which makes up ~25% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~18–30 in this domain), expect 9–15 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)
47questions here
10free pages
8concepts
Questions 1–5
- 1
A legal hold requires an organization to preserve all logs related to a lawsuit for an indefinite period. Which action is most appropriate?
Select an answer first - 2
A company is implementing a new logging policy. They want to ensure that logs are available for incident investigation but also want to minimize the risk of logs being used against them in a legal dispute. Which practice is most appropriate?
Select an answer first - 3
An organization has multiple remote offices with limited bandwidth. They need to centralize logs but want to minimize WAN usage. Which approach is most effective?
Select an answer first - 4
An incident responder is investigating a possible malware infection on a Windows workstation. Which log source would provide the most direct evidence of the initial execution of the malware?
Select an answer first - 5
An analyst is investigating a potential data breach. They have authentication logs, web proxy logs, and database audit logs. The web proxy logs show a user downloading a large file from an internal server, and the database audit logs show a query that returned a large result set. Which correlation would most strongly indicate data exfiltration?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GNFA” is a trademark of its owner, used for identification only.