GSEC Log Management and SIEM Practice Question
A security analyst is investigating a potential data exfiltration incident. The SIEM has ingested firewall logs that show outbound connections, but the analyst notices that the logs do not include the number of bytes transferred. The analyst needs to correlate this with other log sources to estimate the volume of data exfiltrated. Which additional log source would provide the most direct and reliable measurement of data volume for outbound connections?
⚠ Common exam trap
The trap here is assuming that host-based logs or DNS logs contain byte counts for network connections, when only flow-based sources like NetFlow provide that level of detail.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
NetFlow records from core routers and switches.
NetFlow provides byte and packet counts per flow, directly measuring data volume for outbound connections. Firewall logs often lack this detail, so NetFlow is the best additional source to quantify exfiltration. It can be correlated by IP, port, and time to estimate how much data left the network, making it the most direct and reliable choice.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
NetFlow records from core routers and switches.
Why this is correct
NetFlow records include byte and packet counts for each flow, providing a direct measurement of data volume for outbound connections. They are generated by network devices and can be correlated with firewall logs by source/destination IP, port, and timestamp. This allows the analyst to estimate exfiltration volume accurately. NetFlow is widely supported and can be exported to the SIEM, making it the most reliable source for volume data in this scenario.
- ✗
DNS server query logs.
Why it's wrong here
DNS query logs show domain name resolution requests, which can indicate command-and-control or data exfiltration via DNS tunneling, but they do not provide byte counts for outbound connections. While DNS tunneling can exfiltrate data, the volume is usually small and not representative of typical data transfers. For measuring the volume of data over connections, DNS logs are insufficient. They are better for detecting anomalous domains or query patterns.
- ✗
Windows Security event logs from the source host.
Why it's wrong here
Windows Security event logs may record logon events, process creation, and object access, but they do not typically include byte counts for outbound network connections. They could show that a process initiated a connection, but not how much data was transferred. Without network-level volume data, the analyst cannot estimate exfiltration size. This source is useful for host-based activity but not for measuring data volume.
- ✗
Antivirus application logs from the endpoint.
Why it's wrong here
Antivirus logs record malware detections, scan results, and sometimes blocked connections, but they do not measure the volume of data transferred. They might indicate that an exfiltration attempt was blocked, but not how much data left the network. For estimating exfiltration volume, antivirus logs are not a direct or reliable source. They are more useful for identifying known threats on the endpoint.
About these practice questions
Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.