Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Security Leadership

Domain 3Objective 2

Network Monitoring for Managers GSLC Practice Questions (Page 7)

Part of the Security Operations and Incident Management domain, which makes up ~20% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~14–24 in this domain), expect 4–6 from this objective — we provide 52 practice questions to prepare you well beyond it. (estimate)

52questions here
11free pages
7concepts

Questions 31–35

  1. 31expert · hard

    A manager reviews a weekly report showing that a web server's inbound traffic spikes every night at 2:00 AM for 15 minutes, then returns to normal. The traffic is from a single external IP. The IDS has not alerted. What is the most likely explanation?

    Select an answer first
  2. 32expert · hard

    A manager is choosing between two monitoring tools: Tool A provides deep packet inspection (DPI) and can reconstruct sessions, but generates a high volume of alerts and requires significant storage. Tool B provides flow-based analysis (NetFlow) with lower storage requirements and fewer alerts, but cannot inspect packet contents. The organization's priority is detecting advanced persistent threats (APTs) that use encrypted channels. Which tool should the manager choose?

    Select an answer first
  3. 33application · medium

    A security manager reviews the weekly network monitoring report and notices that outbound bandwidth utilization has steadily increased by 15% each week for the past month, while inbound traffic remains flat. The increase is concentrated on a single server that normally generates little traffic. The manager also sees a spike in failed authentication attempts on that server. What is the most appropriate immediate action?

    Select an answer first
  4. 34expert · hard

    A manager must choose between deploying NetFlow and a packet analyzer to monitor a critical application. The application is experiencing intermittent slowdowns, and the security team also wants to detect data exfiltration. The budget allows for only one new tool. Which choice best addresses both needs?

    Select an answer first
  5. 35application · medium

    A manager is reviewing the incident response process after a security incident. The monitoring system generated an alert, but the alert was not acted upon for several hours because the on-call person was not familiar with the alert's meaning. What should the manager implement to prevent this from happening again?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSLC” is a trademark of its owner, used for identification only.