
GIAC Cloud Forensics Responder
Domain 4Objective 3
In-Cloud IR in AWS and Event-Driven Response GCFR Practice Questions (Page 4)
Part of the Amazon Web Services Forensics domain, which makes up ~19% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~13–23 in this domain), expect 4–8 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
12concepts
Questions 16–20
- 16
After creating an EBS snapshot for forensic purposes, what is the recommended way to analyze the data without altering the original evidence?
Select an answer first - 17
To automatically initiate a forensic response when GuardDuty detects a finding, which AWS service can be used to route the finding to a Lambda function?
Select an answer first - 18
A security analyst is investigating a potential data exfiltration from an EC2 instance. The analyst has enabled VPC Flow Logs for the VPC, but the logs are not showing any traffic to an external IP address that was identified in threat intelligence. Which step should the analyst take to ensure the flow logs capture the relevant traffic?
Select an answer first - 19
When using AWS Config to analyze a security group change during an incident, which type of information does AWS Config provide that is most useful for forensic analysis?
Select an answer first - 20
Which AWS service records a history of resource configuration changes that can be used to establish a forensic baseline of an EC2 instance's security groups?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFR” is a trademark of its owner, used for identification only.