
GIAC Network Forensic Analyst
Domain 3Objective 2
Security Event and Incident Logging GNFA Practice Questions (Page 10)
Part of the Security Controls and Monitoring domain, which makes up ~25% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~18–30 in this domain), expect 9–15 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)
47questions here
10free pages
8concepts
Questions 46–47
- 46
An analyst is reviewing logs after a reported incident. They notice that the timestamp on the firewall logs is in UTC, while the authentication server logs use local time. This discrepancy is causing confusion. What is the best practice to avoid this issue?
Select an answer first - 47
A security analyst is reviewing logs after a suspected data exfiltration. They find a large outbound transfer to an external IP at 3:00 AM. Which additional log source would best help confirm whether this was an actual incident or a scheduled backup?
Select an answer first
Finished these 2 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GNFA
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GNFA” is a trademark of its owner, used for identification only.