
GIAC Security Essentials
Domain 5Objective 2
Log Management & SIEM GSEC Practice Questions (Page 1)
Part of the Security Operations and Incident Response domain, which makes up ~16% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~15–26 in this domain), expect 4–7 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)
48questions here
10free pages
8concepts
Questions 1–5
- 1
A financial institution must retain audit logs for at least seven years to meet regulatory requirements. The SIEM storage is expensive, and the security team wants to reduce costs without violating compliance. Which strategy is most appropriate?
Select an answer first - 2
Which of the following is an example of a threshold-based correlation rule?
Select an answer first - 3
A financial institution is required by PCI DSS to retain audit logs for at least one year, with the ability to immediately access the most recent three months. The SIEM currently stores all logs for 90 days in hot storage. What should the institution do to meet the requirement?
Select an answer first - 4
During an incident response, an analyst discovers that the SIEM did not alert on a series of suspicious activities because the relevant logs were not being collected from a critical server. The server's logs are stored locally and are not forwarded to the SIEM. What is the most important immediate action?
Select an answer first - 5
What is the primary function of a correlation rule in a SIEM?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSEC” is a trademark of its owner, used for identification only.