GIAC · Certified Enterprise Defender GCED

GIAC Certified Enterprise Defender GCED Exam Practice Questions

88 questionsPDF by emailUpdated September 2026

US$39

Try 10 questions free

Card, Apple Pay or Google Pay. Your PDF is sent by email as soon as you check out.

Pass or your money backFail the exam after using this pack and we refund it. How the guarantee works
Category:
TRY BEFORE YOU BUY

Three of the 88 questions in this pack

Question 1

Which type of media should the IR team be handling as they seek to understand the root cause of an incident?

  1. Restored media from full backup of the infected host
  2. Media from the infected host, copied to the dedicated IR host
  3. Original media from the infected host
  4. Bit-for-bit image from the infected host
Show answer and explanation

Correct answer: D. Bit-for-bit image from the infected host

A bit-for-bit image is the correct forensic evidence to use during incident investigation. This creates an exact duplicate of the original media at the binary level, preserving all data including deleted files and unallocated space, while maintaining chain of custody. This approach allows analysis without risking modification of original evidence and enables multiple independent investigations.

Why the other options are wrong

  • A. Restored backups may lack malware artifacts and forensic evidence needed to understand the attack.
  • B. Copied media to another host introduces the risk of modification during transfer and may not preserve all forensic details.
  • C. Handling original media directly risks contamination, modification, and loss of chain of custody required for forensic validity.

Question 2

An incident response team is handling a worm infection among their user workstations. They created an IPS signature to detect and block worm activity on the border IPS, then removed the worms artifacts or workstations triggering the rule. Despite this action, worm activity continued for days after. Where did the incident response team fail?

  1. The team did not adequately apply lessons learned from the incident
  2. The custom rule did not detect all infected workstations
  3. They did not receive timely notification of the security event
  4. The team did not understand the worm’s propagation method
Show answer and explanation

Correct answer: D. The team did not understand the worm’s propagation method

method The team failed to understand the worm's propagation method. If worm activity continued after blocking at the IPS and removing artifacts from detected workstations, the team did not identify the actual transmission mechanism, whether it was via email, network shares, USB drives, or another vector. Without understanding how the worm spreads, containment efforts were incomplete and reinfection could occur.

Why the other options are wrong

  • A. Lessons learned apply to preventing future incidents, not explaining why containment failed in the current event.
  • B. The rule may have been functioning correctly; the problem was ongoing propagation through an unblocked vector.
  • C. Delayed notification would not explain continued activity after initial remediation actions were taken.

Question 3

A legacy server on the network was breached through an OS vulnerability with no patch available. The server is used only rarely by employees across several business units. The theft of information from the server goes unnoticed until the company is notified by a third party that sensitive information has been posted on the Internet. Which control was the first to fail?

  1. Security awareness
  2. Access control
  3. Data classification
  4. Incident response
Show answer and explanation

Correct answer: C. Data classification

Data classification was the first control to fail. If sensitive information was stored on a rarely-used legacy server without appropriate protections or access controls, the organization had not properly classified its data or applied commensurate security measures. Proper data classification would have identified that sensitive information should not reside on an unpatched system, triggering compensating controls or data relocation before a breach occurred.

Why the other options are wrong

  • A. Security awareness training does not directly address the placement of sensitive data on vulnerable systems.
  • B. Access control failures would be a downstream issue after data was already improperly classified and stored.
  • D. Incident response is the process of handling breaches after they occur, not a preventive control against data exposure.

See all 10 free questions Get the full pack, US$39

88 practice questions for GIAC Certified Enterprise Defender (GCED), with full explanations.

Every question comes with the correct answer, the reasoning behind it, and a short note on why each wrong option is wrong. Work through it once with the answers, then again with the questions-only copy under exam conditions.

  • 88 questions mapped to the GCED exam objectives
  • Answers and explanations for every question, including the wrong options
  • A questions-only PDF for timed practice runs
  • Instant delivery by email the moment you check out
  • Free monthly updates for as long as the exam is live
  • Pass or your money back

A GCED attempt costs US$999. This pack is US$39, paid once.

Try 10 questions free before you buy.

Last updated September 2026 · 88 questions

What makes the GCED hard

The GCED is GSEC’s harder sibling, covering the same defensive territory but at the depth where the questions expect candidates to read packet captures and defend the choice of control, not just name it.

The bank goes technical fast: network traffic analysis and IDS signatures, defensible architecture and segmentation decisions, malware behaviour and endpoint response, vulnerability assessment interpretation, and the penetration testing concepts a defender needs to anticipate.

Like every GIAC exam it is open book, and like every GIAC exam the clock beats anyone whose index is not ready. 115 questions in three hours at 69% to pass is roughly 94 seconds a question, so looking everything up is not a strategy. The GSEC and GCIH question banks are a natural next step from this one.

About the exam

GCED certifies advanced enterprise defence skills beyond GSEC: defensive network infrastructure, packet and traffic analysis, penetration testing awareness, incident handling, and malware response. It is aligned to the SANS Advanced Security Essentials, Enterprise Defender course. Open book, proctored, DoD 8140 mapped. Valid for four years with CPEs.

Exam topics

  • Defensive network infrastructure and architecture
  • Packet analysis and network security monitoring
  • Penetration testing concepts for defenders
  • Vulnerability assessment and management
  • Incident response and malware analysis fundamentals

115 questions, 3 hours, passing score 69%, open book, US$999 per attempt, valid 4 years.

Reviews

There are no reviews yet.

Only logged in customers who have purchased this product may leave a review.

Questions before you buy

What do I get when I buy the GIAC Certified Enterprise Defender GCED pack?

88 practice questions as a PDF, each with the correct answer, a full explanation and a note on why the other options are wrong, plus a separate questions-only PDF for timed practice.

How quickly do I receive it?

Your PDF is prepared and sent to your email address after checkout, and you get a confirmation as soon as it is on its way.

Is there a free sample?

Yes. Ten questions from this pack, with answers and explanations, are free on this page and as a PDF, so you can judge the quality before you pay.

Are updates included?

Yes. The pack is updated every month for as long as the exam is live, and updates are free for everyone who has bought it.

What if I fail the exam?

We refund the pack. Sit the exam 7 to 30 days after buying, then send your official score report within 7 days of the exam date, as set out in the refund policy.

Can I share it with colleagues?

Each purchase is licensed to one person. For a team, school or training organisation, email support@certstash.com for a licence that fits.