
GIAC Network Forensic Analyst
Domain 3Objective 2
Security Event and Incident Logging GNFA Practice Questions (Page 3)
Part of the Security Controls and Monitoring domain, which makes up ~25% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~18–30 in this domain), expect 9–15 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)
47questions here
10free pages
8concepts
Questions 11–15
- 11
Which of the following is an example of a network device log source?
Select an answer first - 12
Which statement best describes the role of security event logging in incident detection?
Select an answer first - 13
What is the primary purpose of security event logging in an organization?
Select an answer first - 14
A network forensic analyst is investigating a suspected port scan against a server. Which log source would provide the most direct evidence of the scan?
Select an answer first - 15
In the context of incident logging, what constitutes an incident?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GNFA” is a trademark of its owner, used for identification only.