
GIAC Certified Detection Analyst
Domain 2Objective 1
Azure and AWS Logging Overview GCDA Practice Questions (Page 4)
Part of the Cloud and Microsoft Security Analytics domain, which makes up ~17% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 5–7 from this objective — we provide 31 practice questions to prepare you well beyond it. (estimate)
31questions here
7free pages
3concepts
Questions 16–20
- 16
An AWS administrator needs to monitor CPU utilization of an EC2 instance and receive an alert when it exceeds 80% for 10 minutes. Which AWS service should be used to create this alarm?
Select an answer first - 17
A security team needs to query Azure AD sign-in logs and Azure resource activity logs together using KQL. They want to keep the data in a single repository for long-term retention and advanced analytics. What should they configure?
Select an answer first - 18
Which of the following correctly pairs an Azure logging service with its AWS equivalent?
Select an answer first - 19
A security team wants to query logs from multiple Azure resources, including VMs, App Services, and Azure AD, in one place using a single query language. Which Azure service should they use?
Select an answer first - 20
A security analyst is troubleshooting a detection rule that should trigger when a user creates a new Azure role assignment. The rule queries the Activity Log, but it is not firing. The analyst confirms the user did create a role assignment. What is the most likely reason the rule is not firing?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCDA” is a trademark of its owner, used for identification only.