Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Detection Analyst

Domain 2Objective 1

Azure and AWS Logging Overview GCDA Practice Questions (Page 2)

Part of the Cloud and Microsoft Security Analytics domain, which makes up ~17% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 5–7 from this objective — we provide 31 practice questions to prepare you well beyond it. (estimate)

31questions here
7free pages
3concepts

Questions 6–10

  1. 6application · medium

    A company runs a hybrid environment with Azure VMs and AWS EC2 instances. The security team needs to detect unauthorized configuration changes across both clouds and correlate them with user identity. Which combination of logs should be collected to meet this need?

    Select an answer first
  2. 7expert · medium

    A company is migrating from on-premises to Azure and AWS. They need to ensure that security logs are available for incident response within 15 minutes of an event. Which approach meets this requirement?

    Select an answer first
  3. 8expert · hard

    A security architect is designing a logging strategy for a new application that will run in both Azure and AWS. The application will generate custom security events that need to be correlated across both clouds. The team wants to use a single query interface and minimize the number of tools. Which approach best meets these requirements?

    Select an answer first
  4. 9expert · hard

    A security team is investigating a possible data breach involving an EC2 instance. They have CloudTrail logs showing API calls, but they need to determine if data was actually exfiltrated over the network. They also need to see if any security group rules were changed to allow outbound traffic. Which combination of AWS logs should they analyze?

    Select an answer first
  5. 10expert · medium

    A security architect is designing a multi-cloud logging solution for a financial institution. The institution requires that all cloud audit logs be retained for 7 years and be immutable to satisfy regulatory requirements. They also need to run complex queries across Azure and AWS logs for threat hunting. The budget is limited, so they want to minimize storage costs while maintaining query performance. Which solution best meets these requirements?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCDA” is a trademark of its owner, used for identification only.