
GIAC Cloud Security Architecture and Design
Domain 4Objective 2
Orchestrating Log Integrations for Operational Value GCAD Practice Questions (Page 7)
Part of the Logging, Monitoring, and Incident Response domain, which makes up ~19% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–15 in this domain), expect 3–5 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
10concepts
Questions 31–35
- 31
A company's SIEM receives logs from VPN gateways and identity providers. The security team wants to automatically detect when a user authenticates to the VPN from a new geographic location and then accesses a sensitive application within 10 minutes. What is the most effective approach?
Select an answer first - 32
An operations team wants to monitor a cloud application for unusual error rates. They have integrated logs into a monitoring platform. What should they configure to be notified immediately when the error rate exceeds a threshold?
Select an answer first - 33
Which of the following is a typical step in parsing a raw log entry?
Select an answer first - 34
What is the primary goal of log correlation across multiple sources?
Select an answer first - 35
An organization is preparing for an external audit that requires proof that logs have not been tampered with and that access to logs is logged. What should the organization implement to satisfy the auditor?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCAD” is a trademark of its owner, used for identification only.