Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Cloud Security Architecture and Design

Domain 4Objective 1

Comprehensive Logging and Aggregation GCAD Practice Questions (Page 8)

Part of the Logging, Monitoring, and Incident Response domain, which makes up ~19% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–15 in this domain), expect 3–5 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)

53questions here
11free pages
8concepts

Questions 36–40

  1. 36application · medium

    A company has a distributed microservices architecture running on Kubernetes. They want to aggregate logs from all pods into a central system for searching and alerting. Which approach is most efficient and scalable for collecting logs from Kubernetes?

    Select an answer first
  2. 37expert · hard

    A security operations center is investigating a series of suspicious activities. They notice that a user's account was used to log in from two different geographic locations within a short time period, and then the same account was used to modify firewall rules. Which correlation of logs would most effectively identify this as a potential account compromise?

    Select an answer first
  3. 38application · medium

    A company is required by regulation to retain logs for at least three years and must be able to prove that logs have not been modified. They are using a SIEM for real-time monitoring and a separate storage system for long-term retention. Which configuration provides the strongest tamper-evidence for the retained logs?

    Select an answer first
  4. 39application · medium

    A company is migrating a legacy application to the cloud. The application runs on virtual machines and uses a managed database. The security team wants to ensure that all security-relevant events are captured. Which logging architecture should they implement?

    Select an answer first
  5. 40expert · hard

    A security team is evaluating SIEM solutions. They have a high volume of logs (several terabytes per day) and need to support complex correlation queries. They also have a limited budget and want to avoid over-provisioning infrastructure. Which deployment model is most suitable?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCAD” is a trademark of its owner, used for identification only.