Domain 4: Continuous Security Monitoring (SIEM, threat intel, anomaly detection)
GIAC Certified Enterprise Defender · 32 questions
- A SOC receives threat intelligence indicating that an APT group uses a specific user-agent string in HTTP requests. Which SIEM query approach most efficiently detects this across all web proxy logs?
- A threat intelligence analyst receives an indicator of compromise (IOC) consisting of an IP address associated with a known botnet C2. The IOC is 6 months old. What factor most affects the reliability of this IOC?
- A SIEM rule is generating 500 alerts per day but only 2 are confirmed incidents. The SOC team is overwhelmed. What is this situation called and what is the best remediation?
- A SIEM analyst creates a use case to detect user accounts logging in from two geographically distant locations within a short time window. What type of detection is this?
- Which standard framework maps attacker techniques and sub-techniques to specific detection data sources and mitigation controls, making it highly useful for continuous security monitoring?
- A continuous security monitoring program tracks Mean Time to Detect (MTTD). A SOC reduces MTTD from 72 hours to 4 hours. What is the primary security benefit of this improvement?
- A threat hunter suspects an attacker is using DNS tunneling for data exfiltration. Which SIEM query characteristic most effectively detects this technique?
- A continuous monitoring program identifies a spike in failed authentication attempts against a domain controller at 2 AM. The attempts use valid usernames but wrong passwords. Which attack technique does this most likely represent?
- A SIEM correlation rule fires when a single user account logs in from more than 3 distinct source IP addresses within 10 minutes. An alert triggers for a service account. The analyst notes the service account is used by a load-balanced application cluster with 8 nodes. What should the analyst do?
- A threat intelligence platform receives a STIX 2.1 report describing an APT group's tactics. The report includes a Relationship object linking a Malware object to a Campaign object. What does this relationship describe?
- An organization collects logs from 500 endpoints but only retains them for 7 days before deletion to manage storage costs. A security incident is discovered 15 days after the initial compromise. What critical problem does this retention policy create?
- A SOC uses the MITRE ATT&CK framework to map coverage. An analyst notes that Technique T1055 (Process Injection) has no detection rules in the SIEM. What data source should be prioritized to build detection for this technique?
- A security operations center wants to measure how long it takes from when a threat is first observed in the environment to when it is fully remediated. Which metric does this describe?
- A security engineer is deploying a SIEM and needs to onboard Windows Domain Controller logs. Which Windows Security event category must be enabled via Group Policy to capture user account management events such as group membership changes?
- A threat intelligence team classifies IOCs using the Pyramid of Pain framework. Which level of indicator is most valuable and hardest for an attacker to change?
- An analyst is configuring a SIEM to baseline normal user behavior and detect anomalies. The SIEM vendor calls this feature UEBA (User and Entity Behavior Analytics). What specific advantage does UEBA provide over static threshold-based detection rules?
- What is the difference between a SIEM use case and a SIEM correlation rule?
- A SOC team wants to implement threat hunting to proactively find attackers who evaded existing detection. What best describes the threat hunting methodology?
- A SOC analyst observes a SIEM alert for an internal host making HTTP connections to 50 different external IP addresses in 10 minutes, all on port 80, with 8-byte responses and no follow-on traffic. What does this most likely indicate?
- Which threat intelligence sharing platform and protocol enables automated machine-to-machine exchange of threat indicators in a standardized format?
- A security operations team implements a security orchestration, automation, and response (SOAR) platform. Which primary benefit does SOAR provide over a traditional SIEM alone?
- A security operations team wants to reduce noise in their SIEM by implementing log source normalization. What does normalization accomplish?
- A SOC analyst receives a high-priority alert: 'Lateral Movement Detected — SMB connection from workstation to domain controller using local admin credentials.' What is the most critical first investigative step?
- A threat intelligence analyst wants to measure the quality of IOCs being consumed by the SIEM. Which metric most accurately reflects IOC quality in operational use?
- A SIEM is ingesting Windows Security event logs. An analyst wants to detect when an account is added to a privileged group such as Domain Admins. Which Windows Event ID should trigger the detection rule?
- A security analyst is building a detection for Kerberoasting in the SIEM using Windows Security event logs. Which Event ID indicates that a Kerberos service ticket was requested for an account with an SPN?
- A SIEM analyst creates a detection rule that fires when a user account logs in successfully after 5 or more failed attempts within 10 minutes. What attack does this detect and what are the potential false positive scenarios?
- An organization wants to implement a Security Operations Center maturity model. Which capability represents the highest maturity level?
- A threat intelligence analyst receives a report indicating that a specific APT group is targeting organizations in the same industry sector using spear-phishing emails with malicious PDF attachments. How should a defensive SOC operationalize this intelligence?
- A SOC analyst is building a correlation rule to detect Golden Ticket attacks in Active Directory. Which Windows Security event sequence is most indicative of a Golden Ticket attack?
- An organization wants to implement a vulnerability management program with risk-based prioritization. Beyond the CVSS base score, which additional factor most significantly changes the effective risk of a vulnerability?
- A security analyst is configuring a SIEM to detect potential data exfiltration. Which combination of data sources and correlation logic is most effective for this use case?