Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS)

GIAC Cloud Forensics Responder

GCFR

The GIAC Cloud Forensics Responder (GCFR) certification validates your ability to track and respond to incidents across the three major cloud providers: Amazon Web Services, Google Cloud, and Microsoft Azure. Built for incident responders, SOC analysts, and threat hunters, it proves you can collect and interpret cloud-native logs, identify malicious activity, and extract forensic evidence to determine root cause. Earning GCFR demonstrates that you are prepared to manage rapidly changing enterprise cloud environments with hands-on, real-world skills.

554 practice questions · Updated 2026-07-30

6Domains
15Objectives
124Concepts
554Questions

GCFR Curriculum

Every domain, objective, and concept the GCFR exam measures.

Introduction to Cloud DFIR

9 concepts · 47 questions
  1. Cloud DFIR Overview
  2. Cloud Service Models
  3. Cloud Deployment Models
  4. Shared Responsibility Model
  5. Cloud Forensic Challenges
  6. Cloud Forensic Frameworks
  7. Cloud DFIR Process
  8. Cloud Evidence Sources
  9. Legal and Compliance Considerations

Google Cloud Overview and IAM

5 concepts · 33 questions
  1. Google Cloud Platform (GCP) Overview
  2. IAM Roles and Permissions
  3. IAM Policy Structure
  4. IAM Best Practices for Forensics
  5. Audit Logging and IAM

Google Cloud Storage and Networking

10 concepts · 37 questions
  1. Google Cloud Storage forensic acquisition
  2. Google Cloud Storage metadata analysis
  3. Google Cloud Storage access logging and audit trails
  4. Google Cloud VPC flow logs analysis
  5. Google Cloud firewall rules and network security analysis
  6. Google Cloud packet capture and traffic acquisition
  7. Google Cloud DNS logs and resolution analysis
  8. Google Cloud load balancer logs analysis
  9. Google Cloud network topology mapping
  10. Google Cloud VPN and interconnect forensics

Google Cloud Virtual Machines

12 concepts · 41 questions
  1. Virtual Machine Lifecycle
  2. VM Metadata and Instance Attributes
  3. Disk Types and Snapshots
  4. Startup and Shutdown Scripts
  5. Serial Console Output
  6. VM Network Configuration
  7. OS Login and SSH Keys
  8. Instance Templates and Groups
  9. Confidential VM and Shielded VM
  10. VM Migration and Live Migration
  11. Logging and Monitoring Integration
  12. Forensic Acquisition from VMs

Log Sources for Google Cloud IR

9 concepts · 34 questions
  1. Identify GCP log sources
  2. Understand Cloud Logging
  3. Differentiate log types
  4. Access logs via Console
  5. Access logs via API
  6. Export logs to external systems
  7. Correlate logs with resources
  8. Understand log retention
  9. Recognize log integrity considerations

Google Workspace Fundamentals

5 concepts · 37 questions
  1. Google Workspace Data Storage
  2. Google Workspace Administration
  3. Google Workspace Logging and Auditing
  4. Google Workspace APIs and Data Access
  5. Google Workspace Retention and eDiscovery
  1. Accessing Google Workspace Evidence
  2. Investigating Google Workspace Evidence

Understanding IR in AWS

6 concepts · 23 questions
  1. AWS Incident Response Fundamentals
  2. AWS Shared Responsibility Model in Forensics
  3. AWS Forensic Data Sources
  4. AWS Forensic Artifacts Collection
  5. AWS Forensic Analysis Techniques
  6. AWS Forensic Investigation Workflow

AWS Networking, VMs, and Storage

7 concepts · 36 questions
  1. AWS VPC Fundamentals
  2. VPC Flow Logs
  3. AWS Network Firewall and Security Groups
  4. EC2 Instance Forensics
  5. EBS Volume Analysis
  6. S3 Bucket Forensics
  7. AWS Storage Gateway and Other Storage Services
  1. AWS Incident Response Fundamentals
  2. AWS CloudTrail for Forensics
  3. AWS Config and Resource State Analysis
  4. VPC Flow Logs Analysis
  5. EC2 Snapshot and Volume Forensics
  6. Lambda for Automated Response
  7. Event-Driven Response with CloudWatch Events
  8. GuardDuty Integration for Threat Detection
  9. Step Functions for Orchestrated Response
  10. Evidence Preservation and Chain of Custody in AWS
  11. AWS Security Hub for Centralized Visibility
  12. S3 and Glacier for Forensic Data Storage

  1. Azure Core Concepts
  2. Azure Resource Types
  3. Azure Log Sources Overview
  4. Azure Activity Logs
  5. Azure Resource Logs
  6. Azure AD Logs
  7. Log Retention and Storage
  8. Log Correlation and Analysis

Microsoft Azure Virtual Machines

10 concepts · 43 questions
  1. Azure VM Architecture
  2. VM Deployment Models
  3. VM Storage and Disks
  4. VM Networking
  5. VM Lifecycle and States
  6. Azure VM Extensions
  7. VM Logging and Monitoring
  8. VM Snapshot and Backup Forensics
  9. VM Security and Access Control
  10. VM Data Collection Methods

Microsoft Azure Storage and Networking

14 concepts · 47 questions
  1. Azure Storage Account Types
  2. Azure Blob Storage Access Tiers
  3. Azure Storage Redundancy Options
  4. Azure Storage Security Features
  5. Azure Storage Logging and Monitoring
  6. Azure Virtual Network (VNet) Fundamentals
  7. Azure Network Security Groups (NSGs)
  8. Azure Firewall and DDoS Protection
  9. Azure Load Balancer and Application Gateway
  10. Azure VPN Gateway and ExpressRoute
  11. Azure DNS and Traffic Manager
  12. Azure Network Watcher
  13. Azure Storage and Network Forensics Data Sources
  14. Azure Storage and Network Incident Response Procedures
  1. Unified Audit Log Overview
  2. Accessing the Unified Audit Log
  3. Audit Log Schema and Fields
  4. Graph API Fundamentals
  5. Graph API Authentication
  6. Querying Audit Logs with Graph API
  7. Interpreting Audit Log Data
  8. Correlating Audit Logs with Other Data
  9. Retention and Export of Audit Logs

  1. Kubernetes Architecture
  2. Kubernetes Objects
  3. Kubernetes Logging Fundamentals
  4. Log Collection Methods
  5. Common Kubernetes Attacks
  6. Attack Detection via Logs
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.

Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for GCFR, so none is invented.