
GIAC Cloud Forensics Responder
Domain 3Objective 1
Google Workspace Fundamentals GCFR Practice Questions (Page 5)
Part of the Google Workspace Forensics domain, which makes up ~10% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~7–12 in this domain), expect 4–6 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
5concepts
Questions 21–25
- 21
An investigator needs to determine whether a user shared a specific Drive file with an external party and when that sharing occurred. Which log should be examined?
Select an answer first - 22
An incident responder needs to retrieve a list of all files in a user's Google Drive, including files shared with the user, along with their permissions and last modified timestamps. The responder has been granted appropriate admin privileges. Which API should be used?
Select an answer first - 23
An incident responder needs to collect all Drive files shared with an external user, including files that the external user may have deleted from their own Drive. The organization has Vault with Drive retention enabled. What is the most effective approach?
Select an answer first - 24
An investigator needs to programmatically retrieve a list of all users in a Google Workspace domain, including their status and last login time. Which API should be used?
Select an answer first - 25
A forensic investigator needs to determine which administrator deleted a user's account in Google Workspace. The organization has enabled Admin audit logs. Which log should be examined?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFR” is a trademark of its owner, used for identification only.