
GIAC Cloud Forensics Responder
Domain 2Objective 3
Google Cloud Virtual Machines GCFR Practice Questions (Page 2)
Part of the Google Cloud Platform Forensics domain, which makes up ~26% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~18–31 in this domain), expect 5–8 from this objective — we provide 41 practice questions to prepare you well beyond it. (estimate)
41questions here
9free pages
12concepts
Questions 6–10
- 6
What is the primary purpose of an instance template in Google Cloud?
Select an answer first - 7
A forensic investigator needs to preserve the disk of a running VM that is suspected of containing malware. The VM uses a standard persistent disk. To minimize changes to the live system while ensuring a forensically sound copy, what should the investigator do first?
Select an answer first - 8
An analyst is tracing the network activity of a compromised VM. The VM has an internal IP and a public IP. The analyst needs to identify all connections made to the VM's public IP. Which data source would provide the most comprehensive record of these connections?
Select an answer first - 9
To capture serial console output for forensic analysis, which setting must be enabled on the VM?
Select an answer first - 10
An investigator is analyzing a Google Cloud VM that was accessed via SSH using OS Login. The investigator suspects that an IAM principal was compromised. The VM's OS Login logs show a successful login from an IP address. The investigator needs to determine if the IAM principal's credentials were used from that IP. Which additional data source should the investigator correlate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFR” is a trademark of its owner, used for identification only.