
GIAC Security Essentials
Domain 5Objective 2
Log Management & SIEM GSEC Practice Questions (Page 9)
Part of the Security Operations and Incident Response domain, which makes up ~16% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~15–26 in this domain), expect 4–7 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)
48questions here
10free pages
8concepts
Questions 41–45
- 41
A SIEM correlation rule is designed to detect a possible credential stuffing attack by alerting when the same source IP attempts to log in with multiple different usernames. The rule is not firing even though the attack is occurring. The analyst has verified that the logs are being ingested and the rule is enabled. What is the most likely cause?
Select an answer first - 42
An analyst receives a SIEM alert indicating a possible privilege escalation on a server. To confirm whether the alert is a true positive, which action should the analyst take first?
Select an answer first - 43
A company is migrating from on-premises servers to a cloud provider. The security team needs to ensure that logs from both environments are collected and normalized in the SIEM. The cloud provider offers a native logging service, while on-premises servers use syslog. What is the most efficient approach?
Select an answer first - 44
A company runs a mix of Linux servers, Windows workstations, and network appliances. The security team needs to centralize logs for analysis. The network appliances only support syslog, while the Windows workstations need to send logs without installing third-party software. Which approach best meets these requirements?
Select an answer first - 45
A SIEM analyst notices that a correlation rule triggers an alert every time a user fails to log in three times within five minutes. The help desk receives many alerts for legitimate users who mistype their passwords. The analyst wants to reduce false positives while still detecting brute-force attacks. Which change is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSEC” is a trademark of its owner, used for identification only.