
GIAC Cloud Forensics Responder
Domain 4Objective 2
AWS Networking, VMs, and Storage GCFR Practice Questions (Page 1)
Part of the Amazon Web Services Forensics domain, which makes up ~19% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~13–23 in this domain), expect 4–8 from this objective — we provide 36 practice questions to prepare you well beyond it. (estimate)
36questions here
8free pages
7concepts
Questions 1–5
- 1
An investigator is examining an S3 bucket that may have been used to exfiltrate data. The bucket has versioning enabled, and the investigator needs to determine whether an object was deleted and then re-uploaded. Which S3 feature provides the most direct evidence of this activity?
Select an answer first - 2
Which AWS component is required to allow resources in a VPC to communicate with the internet?
Select an answer first - 3
Which of the following is a source of forensic information that is unique to an EC2 instance and can be accessed from within the instance?
Select an answer first - 4
What is the primary purpose of VPC Flow Logs in a forensic investigation?
Select an answer first - 5
A responder is investigating a compromised instance that was in a subnet with a network ACL that allows all inbound and outbound traffic. The instance's security group allows inbound SSH from a specific IP range. The responder finds that the attacker connected from an IP outside the allowed range. Which configuration change could have allowed this?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFR” is a trademark of its owner, used for identification only.