
GIAC Cloud Forensics Responder
The GIAC Cloud Forensics Responder (GCFR) certification validates your ability to track and respond to incidents across the three major cloud providers: Amazon Web Services, Google Cloud, and Microsoft Azure. Built for incident responders, SOC analysts, and threat hunters, it proves you can collect and interpret cloud-native logs, identify malicious activity, and extract forensic evidence to determine root cause. Earning GCFR demonstrates that you are prepared to manage rapidly changing enterprise cloud environments with hands-on, real-world skills.
554 practice questions · Updated 2026-07-30
GCFR Curriculum
Every domain, objective, and concept the GCFR exam measures.
- Cloud DFIR Overview
- Cloud Service Models
- Cloud Deployment Models
- Shared Responsibility Model
- Cloud Forensic Challenges
- Cloud Forensic Frameworks
- Cloud DFIR Process
- Cloud Evidence Sources
- Legal and Compliance Considerations
- Google Cloud Platform (GCP) Overview
- IAM Roles and Permissions
- IAM Policy Structure
- IAM Best Practices for Forensics
- Audit Logging and IAM
- Google Cloud Storage forensic acquisition
- Google Cloud Storage metadata analysis
- Google Cloud Storage access logging and audit trails
- Google Cloud VPC flow logs analysis
- Google Cloud firewall rules and network security analysis
- Google Cloud packet capture and traffic acquisition
- Google Cloud DNS logs and resolution analysis
- Google Cloud load balancer logs analysis
- Google Cloud network topology mapping
- Google Cloud VPN and interconnect forensics
- Virtual Machine Lifecycle
- VM Metadata and Instance Attributes
- Disk Types and Snapshots
- Startup and Shutdown Scripts
- Serial Console Output
- VM Network Configuration
- OS Login and SSH Keys
- Instance Templates and Groups
- Confidential VM and Shielded VM
- VM Migration and Live Migration
- Logging and Monitoring Integration
- Forensic Acquisition from VMs
- Identify GCP log sources
- Understand Cloud Logging
- Differentiate log types
- Access logs via Console
- Access logs via API
- Export logs to external systems
- Correlate logs with resources
- Understand log retention
- Recognize log integrity considerations
- Google Workspace Data Storage
- Google Workspace Administration
- Google Workspace Logging and Auditing
- Google Workspace APIs and Data Access
- Google Workspace Retention and eDiscovery
- Accessing Google Workspace Evidence
- Investigating Google Workspace Evidence
- AWS Incident Response Fundamentals
- AWS Shared Responsibility Model in Forensics
- AWS Forensic Data Sources
- AWS Forensic Artifacts Collection
- AWS Forensic Analysis Techniques
- AWS Forensic Investigation Workflow
- AWS VPC Fundamentals
- VPC Flow Logs
- AWS Network Firewall and Security Groups
- EC2 Instance Forensics
- EBS Volume Analysis
- S3 Bucket Forensics
- AWS Storage Gateway and Other Storage Services
- AWS Incident Response Fundamentals
- AWS CloudTrail for Forensics
- AWS Config and Resource State Analysis
- VPC Flow Logs Analysis
- EC2 Snapshot and Volume Forensics
- Lambda for Automated Response
- Event-Driven Response with CloudWatch Events
- GuardDuty Integration for Threat Detection
- Step Functions for Orchestrated Response
- Evidence Preservation and Chain of Custody in AWS
- AWS Security Hub for Centralized Visibility
- S3 and Glacier for Forensic Data Storage
- Azure Core Concepts
- Azure Resource Types
- Azure Log Sources Overview
- Azure Activity Logs
- Azure Resource Logs
- Azure AD Logs
- Log Retention and Storage
- Log Correlation and Analysis
- Azure VM Architecture
- VM Deployment Models
- VM Storage and Disks
- VM Networking
- VM Lifecycle and States
- Azure VM Extensions
- VM Logging and Monitoring
- VM Snapshot and Backup Forensics
- VM Security and Access Control
- VM Data Collection Methods
- Azure Storage Account Types
- Azure Blob Storage Access Tiers
- Azure Storage Redundancy Options
- Azure Storage Security Features
- Azure Storage Logging and Monitoring
- Azure Virtual Network (VNet) Fundamentals
- Azure Network Security Groups (NSGs)
- Azure Firewall and DDoS Protection
- Azure Load Balancer and Application Gateway
- Azure VPN Gateway and ExpressRoute
- Azure DNS and Traffic Manager
- Azure Network Watcher
- Azure Storage and Network Forensics Data Sources
- Azure Storage and Network Incident Response Procedures
- Unified Audit Log Overview
- Accessing the Unified Audit Log
- Audit Log Schema and Fields
- Graph API Fundamentals
- Graph API Authentication
- Querying Audit Logs with Graph API
- Interpreting Audit Log Data
- Correlating Audit Logs with Other Data
- Retention and Export of Audit Logs
- Kubernetes Architecture
- Kubernetes Objects
- Kubernetes Logging Fundamentals
- Log Collection Methods
- Common Kubernetes Attacks
- Attack Detection via Logs
Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for GCFR, so none is invented.