
GIAC Cloud Forensics Responder
Domain 1Objective 1
Introduction to Cloud DFIR GCFR Practice Questions (Page 8)
Part of the Cloud DFIR Foundations domain, which makes up ~8% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~6–10 in this domain), expect 6–10 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)
47questions here
10free pages
9concepts
Questions 36–40
- 36
Which cloud deployment model is characterized by infrastructure that is shared by multiple organizations with similar interests or compliance requirements, often operated by a third party?
Select an answer first - 37
A small business uses a cloud-based customer relationship management (CRM) system. They suspect an insider exfiltrated customer data. Which forensic approach is most appropriate for this SaaS environment?
Select an answer first - 38
During the containment phase of a cloud incident, the responder must preserve evidence while stopping the attacker's access. Which action is most effective for both goals?
Select an answer first - 39
What is the primary purpose of eDiscovery in the context of cloud DFIR?
Select an answer first - 40
Which of the following is a potential source of forensic evidence in a cloud environment?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFR” is a trademark of its owner, used for identification only.