
GIAC Cloud Security Architecture and Design
Domain 4Objective 1
Comprehensive Logging and Aggregation GCAD Practice Questions (Page 9)
Part of the Logging, Monitoring, and Incident Response domain, which makes up ~19% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–15 in this domain), expect 3–5 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)
53questions here
11free pages
8concepts
Questions 41–45
- 41
A company is designing a comprehensive logging architecture for a serverless application. The application uses a function-as-a-service platform, a managed API gateway, and a managed database. The security team wants to detect and investigate potential attacks. Which combination of log sources is most critical?
Select an answer first - 42
Which of the following is an example of a cloud provider log source?
Select an answer first - 43
Which mechanism is commonly used to ensure log integrity and detect tampering?
Select an answer first - 44
A company is designing a log aggregation pipeline for a hybrid cloud environment. They have on-premises servers, AWS, and Azure. The security team wants to centralize logs in a SIEM for real-time alerting, but the network team is concerned about bandwidth usage on the site-to-site VPN. Which approach minimizes bandwidth impact while still providing real-time alerting?
Select an answer first - 45
Which of the following is a key forensic use of logs during incident response?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCAD” is a trademark of its owner, used for identification only.