
GIAC Cloud Forensics Responder
Domain 6Objective 1
Kubernetes Overview, Logs, and Common Attacks GCFR Practice Questions (Page 1)
Part of the Kubernetes Forensics domain, which makes up ~6% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~4–7 in this domain), expect 4–7 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)
32questions here
7free pages
6concepts
Questions 1–5
- 1
An attacker compromises a Kubernetes cluster by exploiting a vulnerable application in a pod. The attacker then uses the pod's service account to access the Kubernetes API and creates a new RoleBinding that grants the service account 'cluster-admin' privileges. Which log source would provide the most direct evidence of this privilege escalation?
Select an answer first - 2
A forensic investigator is trying to determine whether an attacker compromised the etcd datastore of a Kubernetes cluster. Which evidence would most strongly indicate that etcd was accessed directly, rather than through the API server?
Select an answer first - 3
In Kubernetes, where does the kubelet typically store container logs on a worker node so that they are available for retrieval via `kubectl logs`?
Select an answer first - 4
A security analyst is reviewing Kubernetes audit logs and notices a series of API calls from a single service account that include 'list' and 'get' requests for secrets across multiple namespaces, followed by a 'create' of a new pod in the kube-system namespace. The service account is normally used only by a CI/CD pipeline to deploy to the 'dev' namespace. Which action is most appropriate to confirm the suspicion of a compromised credential?
Select an answer first - 5
During incident response, you find that an attacker gained access to a worker node and used the kubelet API to retrieve secrets from all pods on that node. The kubelet was configured with the default authentication mode 'AlwaysAllow'. Which control would have most effectively prevented this attack?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFR” is a trademark of its owner, used for identification only.