
GIAC Security Essentials
Domain 5Objective 2
Log Management & SIEM GSEC Practice Questions (Page 4)
Part of the Security Operations and Incident Response domain, which makes up ~16% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~15–26 in this domain), expect 4–7 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)
48questions here
10free pages
8concepts
Questions 16–20
- 16
A SIEM correlation rule is designed to detect a potential brute-force attack by alerting when the same user account fails to log in 5 times within 5 minutes. The rule is generating a high number of false positives because a legacy application retries authentication automatically. The SOC wants to reduce false positives without missing real attacks. Which modification is most effective?
Select an answer first - 17
Which SIEM component is primarily responsible for identifying relationships between seemingly unrelated events?
Select an answer first - 18
Which of the following is an example of a security-focused log source commonly used in log management?
Select an answer first - 19
A security operations center (SOC) is overwhelmed by SIEM alerts, many of which are false positives. The team wants to improve detection accuracy without increasing staffing. Which combination of actions would be most effective?
Select an answer first - 20
A SIEM is receiving logs from a firewall that uses a proprietary format. The security team wants to create a correlation rule that checks for multiple failed login attempts from the same source IP. What must be done before the rule can work effectively?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSEC” is a trademark of its owner, used for identification only.