
GIAC Cloud Forensics Responder
Domain 2Objective 1
Google Cloud Overview and IAM GCFR Practice Questions (Page 5)
Part of the Google Cloud Platform Forensics domain, which makes up ~26% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~18–31 in this domain), expect 5–8 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)
33questions here
7free pages
5concepts
Questions 21–25
- 21
During an investigation, you need to determine who granted a specific user the Storage Object Admin role on a bucket. Which audit log should you examine?
Select an answer first - 22
A forensic team is investigating a breach that involved a compromised service account. The service account had the Owner role on a project. The team needs to determine what actions the service account performed. Which audit log type would provide the most comprehensive information?
Select an answer first - 23
A forensic investigator needs to understand the relationship between GCP core services and forensic evidence. Which statement is accurate?
Select an answer first - 24
Which type of Cloud Audit Log records activities related to IAM permissions, such as granting or revoking roles?
Select an answer first - 25
A security analyst is investigating a potential privilege escalation. The analyst needs to identify all IAM policies that grant the roles/iam.securityAdmin role to any user in the organization. Which tool or method should the analyst use?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFR” is a trademark of its owner, used for identification only.