
GIAC Network Forensic Analyst
Domain 3Objective 2
Security Event and Incident Logging GNFA Practice Questions (Page 4)
Part of the Security Controls and Monitoring domain, which makes up ~25% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~18–30 in this domain), expect 9–15 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)
47questions here
10free pages
8concepts
Questions 16–20
- 16
A small company wants to implement security event logging for the first time. They have a mix of Windows and Linux servers, a firewall, and a web application. The IT manager wants a simple solution that provides a central view of all security-relevant events without requiring a dedicated security team. Which approach is most appropriate?
Select an answer first - 17
What is a recommended best practice for protecting logs from tampering?
Select an answer first - 18
How does incident logging support the incident response process?
Select an answer first - 19
An organization is investigating a phishing campaign that resulted in a user downloading a malicious attachment. Which combination of log sources would provide the most complete picture of the attack?
Select an answer first - 20
Why is it important to protect logs from unauthorized access?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GNFA” is a trademark of its owner, used for identification only.