
GIAC Cloud Security Architecture and Design
Domain 2Objective 3
Network Firewalls and Traffic Inspection GCAD Practice Questions (Page 3)
Part of the Network Architecture and Security domain, which makes up ~24% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~12–19 in this domain), expect 3–5 from this objective — we provide 34 practice questions to prepare you well beyond it. (estimate)
34questions here
7free pages
7concepts
Questions 11–15
- 11
What is a key limitation of cloud-native security groups compared to traditional network firewalls?
Select an answer first - 12
Which approach is most effective for monitoring firewall logs in a cloud environment?
Select an answer first - 13
A security operations center (SOC) is investigating a suspected intrusion. The firewall logs show that an internal host made a series of outbound connections to a known malicious IP address on port 445 (SMB). The SOC needs to determine if any data was exfiltrated. What additional data source would be most helpful?
Select an answer first - 14
A security analyst is investigating a potential data breach. The firewall logs show that an internal server made an outbound HTTPS connection to an external IP address that is flagged as malicious. The analyst needs to determine what data was transmitted. What should the analyst do?
Select an answer first - 15
A security engineer is troubleshooting an issue where a stateless firewall is dropping legitimate responses to outbound HTTP requests. The firewall is configured to allow outbound TCP port 80. What is the most likely cause and the appropriate fix?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCAD” is a trademark of its owner, used for identification only.