
GIAC Network Forensic Analyst
Domain 3Objective 2
Security Event and Incident Logging GNFA Practice Questions (Page 7)
Part of the Security Controls and Monitoring domain, which makes up ~25% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~18–30 in this domain), expect 9–15 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)
47questions here
10free pages
8concepts
Questions 31–35
- 31
A company is planning to centralize logs from multiple remote offices. The network links are low-bandwidth and sometimes unreliable. They need to ensure logs are transmitted securely and without loss. Which approach is most appropriate?
Select an answer first - 32
An analyst notices a spike in failed authentication attempts on a VPN gateway, followed by a successful login from the same source IP, and then a large data download from an internal file server. Which type of log correlation would best confirm that this is a single coordinated attack?
Select an answer first - 33
A company is implementing a new SIEM and wants to ensure logs are not lost if the SIEM is unavailable. Which practice is most important to implement?
Select an answer first - 34
An organization is subject to a regulation that requires logs to be retained for 1 year, but a pending lawsuit requires preservation of all logs related to a specific incident. The incident logs are currently scheduled for deletion in 30 days. What is the most appropriate action?
Select an answer first - 35
Which log source would most likely contain records of user authentication attempts on a Windows workstation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GNFA” is a trademark of its owner, used for identification only.