GIAC Certified Enterprise Defender (GCED) Exam Prep
Free practice questions

Free GCED Practice Questions

10 exam-style questions with answers and explanations, straight from our 1,050-question bank. Tap an answer to check yourself. When you're ready, take the scored version in the free practice test.

Start the free practice test → ★★★★★4.9/5 from 2,400+ candidates · No signup

The GCED exam has 115 questions and runs 3 hours.

These 10 free GCED questions are organized by exam domain, so you can see how each part of the GIAC Certified Enterprise Defender (GCED) blueprint is tested. Reveal the answer and explanation under each question.

Domain 1: Defending Network Protocols

Question 1

After an ARP spoofing incident on a user VLAN, an engineer enables Dynamic ARP Inspection (DAI) on the access switches. Users on that VLAN immediately lose connectivity, and the switch logs show ARP packets being dropped on ports connected to legitimate hosts. What is the MOST likely cause?

Show answer & explanation

Correct answer: C - DHCP snooping is not enabled, so DAI has no binding table to validate against

Domain 3: Digital Forensics Concepts and Application

Question 2

Following RFC 3227 guidance on the order of volatility, which of the following sources should be collected EARLIEST during live evidence acquisition?

Show answer & explanation

Correct answer: A - The ARP cache on the running system

Question 3

An analyst runs both windows.pslist and windows.psscan against the same memory image. A process named svchost.exe with PID 3120 appears in the psscan output but does not appear in the pslist output. Which conclusion is BEST supported?

Show answer & explanation

Correct answer: A - The process was deliberately unlinked from the active process list

Domain 4: Incident Response Concepts and Application

Question 4

A SOC analyst confirms that a finance workstation is beaconing to a known command-and-control host. The system is powered on, a user is logged in, and management wants the threat stopped immediately. Legal has indicated the incident may lead to prosecution. Which action should the responder take FIRST?

Show answer & explanation

Correct answer: C - Remove the workstation from the network while leaving it powered on

Question 5

A candidate studying incident response reads that the NIST incident response lifecycle consists of four phases: Preparation; Detection and Analysis; Containment, Eradication, and Recovery; and Post-Incident Activity. Which statement about this model is correct as of 2026?

Show answer & explanation

Correct answer: D - It comes from Revision 2, which Revision 3 superseded in 2025 by realigning to CSF 2.0

Domain 6: Intrusion Detection and Packet Analysis

Question 6

An analyst is reviewing the following Snort rule: alert tcp $EXTERNAL_NET any -> $HOME_NET 445 (msg:"SMB exploit attempt"; flow:established,to_server; content:"|FF|SMB"; sid:1000042; rev:1;) Which traffic will cause this rule to generate an alert?

Show answer & explanation

Correct answer: D - Traffic from an external host into the internal network on port 445, within an established session, flowing toward the server

Domain 7: Malware Analysis Concepts and Basic Analysis Techniques

Question 7

A suspicious executable pulled from a compromised host is submitted to an automated sandbox. The report comes back with no network activity, no file writes, and no registry changes. Static properties analysis, however, shows a high-entropy code section and imports for VirtualAlloc and IsDebuggerPresent. What is the MOST likely explanation?

Show answer & explanation

Correct answer: B - The specimen detected the analysis environment and suppressed its malicious behavior

Domain 8: Network Forensics, Logging, and Event Management

Question 8

During an investigation spanning a firewall, a database server, and a web proxy, an analyst finds that the SIEM displays all three sources in a consistent time zone, yet the reconstructed timeline shows the outbound transfer occurring BEFORE the database query that produced the data. What is the MOST likely root cause?

Show answer & explanation

Correct answer: B - The source system clocks are not synchronized to a common time reference

Domain 9: Network Security Monitoring Concepts and Application

Question 9

A network security monitoring sensor running Zeek observes an internal host opening a single long-lived TLS session to an unfamiliar external IP address. Corporate policy prohibits TLS interception. Which approach will BEST support a determination that data is being exfiltrated?

Show answer & explanation

Correct answer: C - Review conn.log for byte-volume asymmetry and ssl.log for the JA3 fingerprint and certificate details

Domain 11: Penetration Testing Concepts

Question 10

A scanner reports a vulnerability with a CVSS v3.1 Base Score of 9.8 on a server. The server is isolated on an air-gapped segment with no inbound routing from any other network. Which CVSS metric group is designed to let the organization reflect these local conditions in the score?

Show answer & explanation

Correct answer: B - The Environmental metric group

The rest of the GCED blueprint

The GCED exam also covers these domains. Drill them in the full free practice test:

That's 10 of 1,050

The full bank has 1,040 more GCED questions with explanations.

Continue in the free practice test →

View plans