Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Cloud Forensics Responder

Domain 6Objective 1

Kubernetes Overview, Logs, and Common Attacks GCFR Practice Questions (Page 3)

Part of the Kubernetes Forensics domain, which makes up ~6% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~4–7 in this domain), expect 4–7 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)

32questions here
7free pages
6concepts

Questions 11–15

  1. 11application · medium

    An attacker compromises a Kubernetes cluster and creates a Deployment that runs a cryptocurrency miner. The deployment is configured with a single replica. The incident responder wants to prevent the deployment from scaling up and to capture the deployment's configuration for evidence. Which sequence of actions should the responder take?

    Select an answer first
  2. 12expert · hard

    During a forensic investigation, you discover that an attacker used a Kubernetes ServiceAccount token to authenticate to the API server and then created a CronJob that runs every minute to exfiltrate data. The token was found in a public container image in the company's registry. Which combination of controls would have most effectively prevented this attack?

    Select an answer first
  3. 13application · medium

    A responder is analyzing kubelet logs and sees repeated requests to the kubelet's /run/secrets/kubernetes.io/serviceaccount/token endpoint from a pod that is not scheduled on that node. What does this indicate?

    Select an answer first
  4. 14expert · hard

    During incident response, you find that an attacker gained access to the Kubernetes API server using a kubelet client certificate that was valid for a single worker node. The attacker then used that certificate to retrieve secrets from pods running on that node. Which control would have most directly prevented this lateral movement?

    Select an answer first
  5. 15foundation · easy

    Which logging pattern in Kubernetes involves a dedicated container within the same Pod that collects and forwards logs from the application container?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFR” is a trademark of its owner, used for identification only.