
GIAC Cloud Security Architecture and Design
Domain 4Objective 2
Orchestrating Log Integrations for Operational Value GCAD Practice Questions (Page 9)
Part of the Logging, Monitoring, and Incident Response domain, which makes up ~19% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–15 in this domain), expect 3–5 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
10concepts
Questions 41–45
- 41
Which component is essential in a log integration architecture to ensure that logs from different sources can be ingested and processed uniformly?
Select an answer first - 42
Which of the following is an example of an actionable alert configured from log data?
Select an answer first - 43
Which storage tier is most appropriate for logs that must be retained for several years but are rarely accessed?
Select an answer first - 44
When onboarding log sources for a cloud environment, which of the following is a key consideration to ensure complete coverage?
Select an answer first - 45
A company's security team is building a central SIEM. They are ingesting AWS CloudTrail, Azure Active Directory sign-in logs, and on-premises firewall logs. The team wants to detect a single user performing anomalous actions across all three sources. Which approach best enables this analysis?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCAD” is a trademark of its owner, used for identification only.