
GIAC Cloud Forensics Responder
Domain 6Objective 1
Kubernetes Overview, Logs, and Common Attacks GCFR Practice Questions (Page 4)
Part of the Kubernetes Forensics domain, which makes up ~6% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~4–7 in this domain), expect 4–7 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)
32questions here
7free pages
6concepts
Questions 16–20
- 16
A security team wants to implement a centralized logging solution for a Kubernetes cluster that runs both Linux and Windows worker nodes. The team needs to collect logs from all nodes, including kubelet, container runtime, and application logs. Which solution best meets this requirement with minimal operational overhead?
Select an answer first - 17
A Kubernetes cluster has a logging agent deployed as a DaemonSet that collects logs from all nodes and forwards them to a central SIEM. The security team notices that logs from a specific pod are missing from the SIEM. The pod is running and producing logs. What is the most likely cause?
Select an answer first - 18
Which log collection method in Kubernetes deploys a DaemonSet to run a logging agent on every node, collecting logs from all Pods on that node?
Select an answer first - 19
An analyst notices repeated failed `kubectl exec` attempts in API server audit logs followed by a successful `exec` into a Pod. Which type of attack is this pattern most indicative of?
Select an answer first - 20
In a Kubernetes cluster, which component is responsible for maintaining the desired state of the cluster and is part of the control plane?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFR” is a trademark of its owner, used for identification only.