
GIAC Cloud Forensics Responder
Domain 2Objective 3
Google Cloud Virtual Machines GCFR Practice Questions (Page 4)
Part of the Google Cloud Platform Forensics domain, which makes up ~26% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~18–31 in this domain), expect 5–8 from this objective — we provide 41 practice questions to prepare you well beyond it. (estimate)
41questions here
9free pages
12concepts
Questions 16–20
- 16
During an incident response, you discover that a Google Cloud VM runs a cryptocurrency miner every time it boots. The VM was created from an instance template. You need to determine the source of the persistence mechanism. Which of the following should you examine FIRST?
Select an answer first - 17
In a managed instance group, what happens when a VM instance is deleted or becomes unhealthy?
Select an answer first - 18
During an incident response, an analyst needs to identify which user last modified a VM's custom metadata that contains an SSH key. The VM is in a project with Cloud Audit Logs enabled. Which log type should the analyst query to find the modification event?
Select an answer first - 19
Which Google Cloud feature allows you to manage SSH access to VMs using IAM roles instead of managing SSH keys directly?
Select an answer first - 20
During a forensic investigation of a Google Cloud VM, you need to determine whether the VM was stopped and restarted before the incident. Which lifecycle event, when logged, would provide the clearest evidence of this action?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFR” is a trademark of its owner, used for identification only.