
GIAC Cloud Forensics Responder
Domain 1Objective 1
Introduction to Cloud DFIR GCFR Practice Questions (Page 2)
Part of the Cloud DFIR Foundations domain, which makes up ~8% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~6–10 in this domain), expect 6–10 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)
47questions here
10free pages
9concepts
Questions 6–10
- 6
Which characteristic of cloud environments is a key forensic challenge because it can cause evidence to be lost or overwritten quickly?
Select an answer first - 7
Which step of the cloud incident response process involves restoring affected cloud services to a known good state while preserving evidence?
Select an answer first - 8
In a SaaS application, a user's account is compromised and the attacker modifies data. The company needs to determine what changes were made. Which evidence source is most likely to provide this information?
Select an answer first - 9
In the shared responsibility model, which of the following is typically the customer's responsibility in an IaaS environment?
Select an answer first - 10
A company uses a public IaaS cloud. A compromised web server VM is identified. The incident response team needs to collect volatile memory evidence. What is the most practical approach?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFR” is a trademark of its owner, used for identification only.