
GIAC Cloud Security Architecture and Design
Domain 4Objective 1
Comprehensive Logging and Aggregation GCAD Practice Questions (Page 4)
Part of the Logging, Monitoring, and Incident Response domain, which makes up ~19% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–15 in this domain), expect 3–5 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)
53questions here
11free pages
8concepts
Questions 16–20
- 16
What is the primary purpose of a log retention policy?
Select an answer first - 17
A security analyst is reviewing a suspected data exfiltration incident. The attacker is believed to have used a compromised application service account to access sensitive data via the cloud provider's API. Which combination of log sources would provide the most direct evidence of the API calls and the data access?
Select an answer first - 18
During an incident response, an analyst needs to determine whether an attacker accessed a specific database table. The database is hosted on an EC2 instance, and the attacker is believed to have used SQL injection through a web application. Which combination of logs would provide the most complete evidence of the attack path?
Select an answer first - 19
Which of the following is a key feature to look for when selecting a centralized log management tool?
Select an answer first - 20
During a security incident, an analyst needs to reconstruct the attacker's actions across multiple cloud services. The analyst has access to aggregated logs, but the logs are incomplete because some sources were not enabled. Which action would most improve the completeness of the investigation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCAD” is a trademark of its owner, used for identification only.