GCED: GIAC Certified Enterprise Defender Exam Practice Test

176 preguntas disponibles

Gana confianza para GCED: GIAC Certified Enterprise Defender Exam. Practica los conceptos, comprende las respuestas y refuerza tus conocimientos pregunta a pregunta.

Probar una pregunta
Prueba 5 preguntas gratis
No necesitas cuenta. Una cuenta gratuita incluye 20 preguntas de este examen.
Examen de certificación
115 Preguntas del examen
3 horas Límite de Tiempo
Tu práctica
176 Preguntas de práctica
2 horas 56 minutos Tiempo de Práctica
Prueba 5 preguntas gratis
No necesitas cuenta. Una cuenta gratuita incluye 20 preguntas de este examen.
El listón a superar 70 Puntuación mínima publicada para obtener esta certificación.
Explora los temas del examen Objetivos oficiales de GIAC
GIAC176 preguntas de práctica
Temario verificadoVerificado con GIAC official objectivesMetadatos verificados 2026-09-26Cómo verificamos

Descripción y detalles del examen

The GIAC Certified Enterprise Defender (GCED) certification validates a professional's ability to defend enterprise networks through comprehensive threat detection, incident response, and security architecture management. Administered by GIAC, a globally recognized leader in cybersecurity certification, the GCED exam assesses practical, hands-on skills in identifying advanced persistent threats (APTs), implementing defensive countermeasures, and managing enterprise-scale security operations. Achieving this certification demonstrates mastery of the core technical competencies required to protect complex, heterogeneous network environments against sophisticated adversaries. It is a key credential for security analysts, incident responders, and network defenders seeking to prove their expertise in aligning defensive strategies with organizational risk management objectives. The GCED is highly regarded for its rigorous, performance-based validation of skills that are immediately applicable in real-world enterprise security roles, making certified professionals valuable assets in securing critical infrastructure and sensitive data.

Preguntas de Muestra

Elige una respuesta y consulta la explicación para ver cómo funciona la práctica.

Intrusion Detection and Packet Analysis

A packet capture shows repeated SYN packets from many spoofed-looking addresses to one server, with few completed handshakes. Which detection conclusion is best?

Intrusion Detection and Packet Analysis

An analyst sees TCP retransmissions and duplicate ACKs during a file transfer alert. Which conclusion is most careful?

Network Forensics, Logging, and Event Management

During a GCED-aligned enterprise defense review, an investigator uses DHCP logs to identify a host by IP during an incident. Which caveat is most important?

Intrusion Detection and Packet Analysis

A Zeek conn.log entry shows a workstation making thousands of short outbound connections to sequential IPs on TCP/445. Which activity is most likely?

Interactive and Manual Malware Analyses

A binary contains strings for PowerShell commands, WMI classes, and scheduled task names, but dynamic analysis shows no execution. What is the best next step?

Oportunidades profesionales y salario

Salario medio: $129,180mercado de EE. UU.– Information Security Analysts

Fuente: BLS Occupational Employment and Wage Statistics, May 2025 -- Information Security Analysts (SOC 15-1212), US national. Occupation median, not a certification salary. (2025)

Information Security Analysts

Los rangos son cifras del mercado de EE. UU. salvo que se muestre un rango local.

Qué temas cubre este examen

01Defending Network Protocols

Temas

  • The candidate will demonstrate an understanding of commonly-used network protocols and how to defend against protocol attacks. The candidate will demonstrate knowledge of audit techniques and the Center for Internet Security's benchmarks and Critical Security Controls.

Objetivos de aprendizaje

  • The candidate will demonstrate an understanding of commonly-used network protocols and how to defend against protocol attacks. The candidate will demonstrate knowledge of audit techniques and the Center for Internet Security's benchmarks and Critical Security Controls.

02Defensive Infrastructure and Tactics

Temas

  • The candidate will demonstrate basic knowledge of network and cloud-based infrastructure defensive measures, including common detective and preventive controls.

Objetivos de aprendizaje

  • The candidate will demonstrate basic knowledge of network and cloud-based infrastructure defensive measures, including common detective and preventive controls.

03Digital Forensics Concepts and Application

Temas

  • The candidate will demonstrate an understanding of methods and practices of digital forensics. The candidate will demonstrate proficiency in identification of forensic artifacts.

Objetivos de aprendizaje

  • The candidate will demonstrate an understanding of methods and practices of digital forensics. The candidate will demonstrate proficiency in identification of forensic artifacts.

04Incident Response Concepts and Application

Temas

  • The candidate will demonstrate an understanding of continuous incident response processes, and their relationship to threat intelligence practices and the Cyber Kill Chain.

Objetivos de aprendizaje

  • The candidate will demonstrate an understanding of continuous incident response processes, and their relationship to threat intelligence practices and the Cyber Kill Chain.

05Interactive and Manual Malware Analyses

Temas

  • The candidate will demonstrate an understanding of interactive malware behavior analysis, knowledge of analysis tools, and ability to interpret the analysis results. The candidate will demonstrate an understanding of manual malware code reversal, disassembly and decompiling, and of code obfuscation techniques used by malware.

Objetivos de aprendizaje

  • The candidate will demonstrate an understanding of interactive malware behavior analysis, knowledge of analysis tools, and ability to interpret the analysis results. The candidate will demonstrate an understanding of manual malware code reversal, disassembly and decompiling, and of code obfuscation techniques used by malware.

06Intrusion Detection and Packet Analysis

Temas

  • The candidate will demonstrate an understanding of intrusion prevention systems, their placement in the enterprise, and their configuration and tuning. The candidate will demonstrate proficiency in taking action in response to alerts.

Objetivos de aprendizaje

  • The candidate will demonstrate an understanding of intrusion prevention systems, their placement in the enterprise, and their configuration and tuning. The candidate will demonstrate proficiency in taking action in response to alerts.

07Malware Analysis Concepts and Basic Analysis Techniques

Temas

  • The candidate will demonstrate an understanding of the various types of malware, identify symptoms of infection, and methods to analyze malware safely. The candidate will demonstrate an understanding of the benefits and disadvantages of automated and static malware analysis techniques, and to interpret their results.

Objetivos de aprendizaje

  • The candidate will demonstrate an understanding of the various types of malware, identify symptoms of infection, and methods to analyze malware safely. The candidate will demonstrate an understanding of the benefits and disadvantages of automated and static malware analysis techniques, and to interpret their results.

08Network Forensics, Logging, and Event Management

Temas

  • The candidate will demonstrate an understanding of using logs and flows in network forensics, the importance of logging and event management in security operations, and the usage of a SIEM and Security Analytics.

Objetivos de aprendizaje

  • The candidate will demonstrate an understanding of using logs and flows in network forensics, the importance of logging and event management in security operations, and the usage of a SIEM and Security Analytics.

09Network Security Monitoring Concepts and Application

Temas

  • The candidate will demonstrate knowledge of devices that are used in SOCs to monitor networks, their understanding of packet types, packet capture tools, the practice of continuous network monitoring, and advanced issues such as monitoring encrypted traffic.

Objetivos de aprendizaje

  • The candidate will demonstrate knowledge of devices that are used in SOCs to monitor networks, their understanding of packet types, packet capture tools, the practice of continuous network monitoring, and advanced issues such as monitoring encrypted traffic.

10Penetration Testing Application

Temas

  • The candidate will demonstrate familiarity and proficiency using penetration testing tactics and tools against typical types of penetration test targets.

Objetivos de aprendizaje

  • The candidate will demonstrate familiarity and proficiency using penetration testing tactics and tools against typical types of penetration test targets.

11Penetration Testing Concepts

Temas

  • The candidate will demonstrate knowledge of penetration testing scoping, rules of engagement, the tools and tactics used in penetration tests, and reporting test results to the intended audience.

Objetivos de aprendizaje

  • The candidate will demonstrate knowledge of penetration testing scoping, rules of engagement, the tools and tactics used in penetration tests, and reporting test results to the intended audience.

Detalles del Examen GCED | $949 USD | 3 horas

Código del Examen GCED
Proveedor GIAC
Costo del Examen $949 USD
Puntaje Mínimo 70
Límite de Tiempo 3 horas
Preguntas del examen 115
Tipos de Preguntas Opción múltiple (100%)
Política de Repetición Two free practice tests are included with each exam registration. Candidates have a 4-month window to take the exam after registration. Retake fees apply after the first failed attempt. Contact GIAC for specific retake waiting periods.
Formato del Examen Multiple Choice
Supervisión en Línea Disponible

Preguntas Frecuentes

¿Cuáles son los roles laborales típicos para un profesional certificado en GCED?

¿Cuál es el nivel de experiencia recomendado antes de intentar el examen GCED?

¿En qué se diferencia el GCED de otras certificaciones de GIAC como el GCIH?

¿Cuál es el formato y la duración del examen?

¿Se requiere capacitación para presentarse al examen GCED?