GCED: GIAC Certified Enterprise Defender Exam Practice Test
GCED: GIAC Certified Enterprise Defender Exam के लिए अपना आत्मविश्वास बढ़ाएँ। अवधारणाओं का अभ्यास करें, उत्तरों को समझें और हर सवाल के साथ अपना ज्ञान मज़बूत करें।
एक नमूना सवाल आज़माएँपरीक्षा का परिचय और विवरण
GIAC GCED प्रमाणन जो परिधि सुरक्षा, SIEM, निरंतर निगरानी, घटना प्रतिक्रिया, मैलवेयर विश्लेषण, और सुरक्षा संचालन पेशेवरों के लिए उद्यम सुरक्षा रक्षा को कवर करता है।
नमूना प्रश्न
अभ्यास कैसे काम करता है, यह जानने के लिए एक उत्तर चुनें और व्याख्या देखें।
A packet capture shows repeated SYN packets from many spoofed-looking addresses to one server, with few completed handshakes. Which detection conclusion is best?
An analyst sees TCP retransmissions and duplicate ACKs during a file transfer alert. Which conclusion is most careful?
During a GCED-aligned enterprise defense review, an investigator uses DHCP logs to identify a host by IP during an incident. Which caveat is most important?
A Zeek conn.log entry shows a workstation making thousands of short outbound connections to sequential IPs on TCP/445. Which activity is most likely?
A binary contains strings for PowerShell commands, WMI classes, and scheduled task names, but dynamic analysis shows no execution. What is the best next step?
करियर के अवसर और वेतन
जब तक लोकल रेंज न दिखे, ये US मार्केट के आंकड़े हैं।
इस परीक्षा में क्या शामिल है
01Defending Network Protocols
विषय
- The candidate will demonstrate an understanding of commonly-used network protocols and how to defend against protocol attacks. The candidate will demonstrate knowledge of audit techniques and the Center for Internet Security's benchmarks and Critical Security Controls.
सीखने के उद्देश्य
- The candidate will demonstrate an understanding of commonly-used network protocols and how to defend against protocol attacks. The candidate will demonstrate knowledge of audit techniques and the Center for Internet Security's benchmarks and Critical Security Controls.
02Defensive Infrastructure and Tactics
विषय
- The candidate will demonstrate basic knowledge of network and cloud-based infrastructure defensive measures, including common detective and preventive controls.
सीखने के उद्देश्य
- The candidate will demonstrate basic knowledge of network and cloud-based infrastructure defensive measures, including common detective and preventive controls.
03Digital Forensics Concepts and Application
विषय
- The candidate will demonstrate an understanding of methods and practices of digital forensics. The candidate will demonstrate proficiency in identification of forensic artifacts.
सीखने के उद्देश्य
- The candidate will demonstrate an understanding of methods and practices of digital forensics. The candidate will demonstrate proficiency in identification of forensic artifacts.
04Incident Response Concepts and Application
विषय
- The candidate will demonstrate an understanding of continuous incident response processes, and their relationship to threat intelligence practices and the Cyber Kill Chain.
सीखने के उद्देश्य
- The candidate will demonstrate an understanding of continuous incident response processes, and their relationship to threat intelligence practices and the Cyber Kill Chain.
05Interactive and Manual Malware Analyses
विषय
- The candidate will demonstrate an understanding of interactive malware behavior analysis, knowledge of analysis tools, and ability to interpret the analysis results. The candidate will demonstrate an understanding of manual malware code reversal, disassembly and decompiling, and of code obfuscation techniques used by malware.
सीखने के उद्देश्य
- The candidate will demonstrate an understanding of interactive malware behavior analysis, knowledge of analysis tools, and ability to interpret the analysis results. The candidate will demonstrate an understanding of manual malware code reversal, disassembly and decompiling, and of code obfuscation techniques used by malware.
06Intrusion Detection and Packet Analysis
विषय
- The candidate will demonstrate an understanding of intrusion prevention systems, their placement in the enterprise, and their configuration and tuning. The candidate will demonstrate proficiency in taking action in response to alerts.
सीखने के उद्देश्य
- The candidate will demonstrate an understanding of intrusion prevention systems, their placement in the enterprise, and their configuration and tuning. The candidate will demonstrate proficiency in taking action in response to alerts.
07Malware Analysis Concepts and Basic Analysis Techniques
विषय
- The candidate will demonstrate an understanding of the various types of malware, identify symptoms of infection, and methods to analyze malware safely. The candidate will demonstrate an understanding of the benefits and disadvantages of automated and static malware analysis techniques, and to interpret their results.
सीखने के उद्देश्य
- The candidate will demonstrate an understanding of the various types of malware, identify symptoms of infection, and methods to analyze malware safely. The candidate will demonstrate an understanding of the benefits and disadvantages of automated and static malware analysis techniques, and to interpret their results.
08Network Forensics, Logging, and Event Management
विषय
- The candidate will demonstrate an understanding of using logs and flows in network forensics, the importance of logging and event management in security operations, and the usage of a SIEM and Security Analytics.
सीखने के उद्देश्य
- The candidate will demonstrate an understanding of using logs and flows in network forensics, the importance of logging and event management in security operations, and the usage of a SIEM and Security Analytics.
09Network Security Monitoring Concepts and Application
विषय
- The candidate will demonstrate knowledge of devices that are used in SOCs to monitor networks, their understanding of packet types, packet capture tools, the practice of continuous network monitoring, and advanced issues such as monitoring encrypted traffic.
सीखने के उद्देश्य
- The candidate will demonstrate knowledge of devices that are used in SOCs to monitor networks, their understanding of packet types, packet capture tools, the practice of continuous network monitoring, and advanced issues such as monitoring encrypted traffic.
10Penetration Testing Application
विषय
- The candidate will demonstrate familiarity and proficiency using penetration testing tactics and tools against typical types of penetration test targets.
सीखने के उद्देश्य
- The candidate will demonstrate familiarity and proficiency using penetration testing tactics and tools against typical types of penetration test targets.
11Penetration Testing Concepts
विषय
- The candidate will demonstrate knowledge of penetration testing scoping, rules of engagement, the tools and tactics used in penetration tests, and reporting test results to the intended audience.
सीखने के उद्देश्य
- The candidate will demonstrate knowledge of penetration testing scoping, rules of engagement, the tools and tactics used in penetration tests, and reporting test results to the intended audience.