Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Cloud Security Architecture and Design

Domain 4Objective 2

Orchestrating Log Integrations for Operational Value GCAD Practice Questions (Page 8)

Part of the Logging, Monitoring, and Incident Response domain, which makes up ~19% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–15 in this domain), expect 3–5 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)

50questions here
10free pages
10concepts

Questions 36–40

  1. 36expert · hard

    An organization is migrating from on-premises to a multi-cloud environment. They have a SIEM that currently ingests on-premises logs. They need to ensure complete coverage of cloud services, including serverless functions, container orchestration, and SaaS applications. They also need to meet audit requirements for user activity. What is the most comprehensive approach?

    Select an answer first
  2. 37application · medium

    A healthcare organization must maintain audit logs for six years under data protection regulations. They are designing a log integration and need to ensure logs are admissible in legal proceedings. Which combination of controls is most important?

    Select an answer first
  3. 38application · medium

    A security operations team receives logs from firewalls, endpoints, and cloud services in different formats. They want to create a unified dashboard that shows failed login attempts across all sources. What is the most efficient way to enable this?

    Select an answer first
  4. 39application · medium

    A company is onboarding a new cloud service that generates logs in a custom JSON format. The security team wants to automate the ingestion and parsing so that new log sources can be added without manual configuration each time. What should the team implement?

    Select an answer first
  5. 40application · medium

    A SOC team wants to create a dashboard that shows failed login attempts across all cloud and on-premises systems. The logs are already normalized into a common schema with a field named 'event_type' that has values like 'login_failure'. What is the most effective way to build this dashboard?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCAD” is a trademark of its owner, used for identification only.