
GIAC Network Forensic Analyst
Domain 3Objective 2
Security Event and Incident Logging GNFA Practice Questions (Page 8)
Part of the Security Controls and Monitoring domain, which makes up ~25% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~18–30 in this domain), expect 9–15 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)
47questions here
10free pages
8concepts
Questions 36–40
- 36
A small financial firm needs to centralize logs from Windows servers, Linux servers, and a Cisco ASA firewall. They have a limited budget and want to minimize the number of agents deployed. Which approach best meets these requirements?
Select an answer first - 37
A company is implementing a logging strategy for a new cloud-based application. They must meet a compliance requirement to retain logs for 3 years, but they also need to respond quickly to incidents. The application generates a high volume of logs. Which strategy best balances cost, compliance, and operational needs?
Select an answer first - 38
What is the primary purpose of log aggregation?
Select an answer first - 39
Which factor is most important when determining how long to retain security logs?
Select an answer first - 40
A company is deploying a new log aggregation solution. They need to ensure that logs are not lost if the central collector is unavailable. Which configuration should they implement?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GNFA” is a trademark of its owner, used for identification only.