
GIAC Cloud Forensics Responder
Domain 1Objective 1
Introduction to Cloud DFIR GCFR Practice Questions (Page 3)
Part of the Cloud DFIR Foundations domain, which makes up ~8% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~6–10 in this domain), expect 6–10 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)
47questions here
10free pages
9concepts
Questions 11–15
- 11
A company's cloud environment was compromised, and the attacker deleted several virtual machines. The incident response team needs to determine what happened. Which evidence source is most likely to provide information about the deleted VMs?
Select an answer first - 12
During a cloud incident, the response team identifies that the attacker used a compromised API key to create new virtual machines. The team needs to contain the incident while preserving evidence of the attacker's actions. Which combination of actions is most effective?
Select an answer first - 13
A hospital is evaluating cloud options for storing patient records. They require high control over security and compliance, but also want to avoid the cost of building a new data center. Which deployment model best balances control and cost?
Select an answer first - 14
An incident responder needs to collect forensic evidence from a customer-managed virtual machine in an IaaS environment. Which evidence source is typically under the customer's direct control?
Select an answer first - 15
Which of the following is a common phase found in cloud forensic frameworks?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFR” is a trademark of its owner, used for identification only.