
GIAC Cloud Security Architecture and Design
Domain 4Objective 1
Comprehensive Logging and Aggregation GCAD Practice Questions (Page 11)
Part of the Logging, Monitoring, and Incident Response domain, which makes up ~19% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–15 in this domain), expect 3–5 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)
53questions here
11free pages
8concepts
Questions 51–53
- 51
A security analyst is investigating a potential insider threat. The analyst has access to aggregated logs from the cloud provider, the identity provider, the VPN gateway, and the file storage service. The analyst needs to determine whether an employee accessed sensitive files outside of business hours and whether that access was anomalous. Which correlation approach is most effective?
Select an answer first - 52
A security team is investigating a potential insider threat. An employee with access to a cloud storage service is suspected of downloading a large volume of sensitive data. Which log source would provide the most direct evidence of the employee's actions, including the specific files accessed?
Select an answer first - 53
A company operates in a highly regulated industry and must retain logs for five years. They are designing a log aggregation pipeline and want to minimize storage costs while still meeting compliance. Which approach is most cost-effective?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GCAD
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCAD” is a trademark of its owner, used for identification only.