Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Cloud Forensics Responder

Domain 2Objective 2

Google Cloud Storage and Networking GCFR Practice Questions (Page 4)

Part of the Google Cloud Platform Forensics domain, which makes up ~26% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~18–31 in this domain), expect 5–8 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)

37questions here
8free pages
10concepts

Questions 16–20

  1. 16application · medium

    An application behind an HTTPS load balancer experienced a spike in 502 errors. The load balancer logs are enabled. The investigator needs to determine whether the errors were caused by the backend rejecting requests or by the load balancer itself. Which field in the load balancer log would be most useful?

    Select an answer first
  2. 17application · medium

    A security analyst is investigating a potential malware infection. Cloud DNS logging is enabled for the VPC. The analyst suspects that a VM resolved a known malicious domain. Which log entry would provide the most direct evidence of the DNS query?

    Select an answer first
  3. 18foundation · medium

    Which type of Cloud Audit Log records read operations on Cloud Storage objects, such as object gets?

    Select an answer first
  4. 19application · medium

    During an incident response, you discover that a VM in a private subnet was accessed from the internet. The VPC has a firewall rule that allows ingress from 0.0.0.0/0 to TCP port 22. You need to determine whether the firewall rule was the actual path used, or if another mechanism allowed the traffic. Which evidence source would most directly confirm the firewall rule was the enabler?

    Select an answer first
  5. 20application · medium

    A forensic investigator is examining a GCS bucket that was used to exfiltrate data. The bucket has versioning enabled, and the investigator needs to determine exactly when a specific object version was deleted and by which principal. The organization has not enabled Cloud Audit Logs for the bucket. Which combination of actions will provide the most reliable evidence of the deletion event?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFR” is a trademark of its owner, used for identification only.