Domain 4: Continuous Security Monitoring
GIAC Certified Enterprise Defender · 18 questions
- A SIEM analyst needs to establish a behavioral baseline for normal SSH login activity. Which metric combination is MOST useful for effective anomaly detection?
- A continuous security monitoring program receives threat intelligence indicating an APT group is actively exploiting a zero-day in VPN concentrators. The intelligence includes IOCs such as specific IP addresses and file hashes. What is the MOST effective immediate use of this intelligence?
- An organization's SIEM generates 500,000 events per day. The security team wants to prioritize which alerts to investigate first. Which framework BEST guides alert prioritization?
- An organization wants to implement a threat hunting program. Which data source combination provides the MOST value for hunting advanced persistent threats that evade signature-based detection?
- A security team is implementing continuous monitoring and must choose between agent-based and agentless endpoint data collection. Which statement accurately describes the trade-off?
- A SIEM correlation rule fires when more than 10 failed authentication attempts are followed by a successful authentication within 5 minutes from the same source IP. An alert fires for a service account. What should the analyst investigate FIRST?
- An organization's vulnerability management team takes an average of 45 days to remediate critical vulnerabilities. Which metric BEST measures the effectiveness of the remediation program?
- A continuous security monitoring analyst notices a critical server has not reported logs to the SIEM for 72 hours. What is the MOST appropriate response?
- An organization is implementing a SIEM platform. Which log source combination should be prioritized for initial ingestion to maximize threat detection capability?
- A SOC analyst receives an alert from the SIEM: 'User account jsmith logged in from two geographically disparate locations within 10 minutes (New York and Tokyo).' What is the first analytical step to determine if this is a true positive?
- A SIEM correlation rule fires: 'More than 5 failed login attempts followed by a successful login from the same source IP within 2 minutes.' Which attack technique does this rule detect, and what additional context should be collected?
- Your organization subscribes to a commercial threat intelligence feed that provides malicious IP addresses. A new analyst proposes blocking all IPs from the feed at the perimeter firewall immediately. What risk does this approach carry?
- A SIEM analyst notices that Windows Event ID 4624 (successful logon) with Logon Type 3 (network logon) is generated thousands of times per hour on file servers from service accounts. How should the analyst tune the SIEM to reduce alert noise without losing security value?
- An analyst receives a threat intelligence report describing a new APT group using a specific YARA signature pattern in their custom implant. The organization has a SIEM with endpoint telemetry. Which action most effectively operationalizes this intelligence?
- A security operations team wants to establish a baseline for 'normal' DNS query rates per workstation to detect DNS tunneling. Which statistical approach is most appropriate for anomaly detection?
- A SIEM rule generates: 'Privileged group membership change: user svcbackup added to Domain Admins.' No change request ticket exists for this change. What is the correct response workflow?
- A threat hunter is looking for evidence of living-off-the-land (LOtL) techniques on Windows endpoints. Which combination of data sources provides the best hunting surface?
- A threat intelligence analyst receives a report from an ISAC (Information Sharing and Analysis Center) containing a list of IP addresses, domains, and file hashes associated with a threat actor targeting the energy sector. How should this intelligence be prioritized for operationalization?