
GIAC Cloud Forensics Responder
Domain 6Objective 1
Kubernetes Overview, Logs, and Common Attacks GCFR Practice Questions (Page 5)
Part of the Kubernetes Forensics domain, which makes up ~6% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~4–7 in this domain), expect 4–7 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)
32questions here
7free pages
6concepts
Questions 21–25
- 21
Which Kubernetes log source would you examine to detect an attacker creating a new Pod with a privileged container?
Select an answer first - 22
A forensics team needs to collect logs from a Kubernetes cluster where applications write logs to stdout, but the team also needs to capture logs from a legacy application that writes only to a file inside its container. The cluster does not have a node-level logging agent deployed. Which approach ensures both log sources are collected without modifying the application?
Select an answer first - 23
A Kubernetes cluster uses a centralized logging solution that collects logs from all namespaces. The security team wants to ensure that logs from the kube-system namespace are retained for a longer period than other namespaces due to compliance requirements. Which approach should they take?
Select an answer first - 24
A SOC analyst is reviewing Kubernetes audit logs and notices a series of API calls from a single service account that suddenly begins creating pods with hostPID: true and mounting the host filesystem. The account had no prior history of creating pods. Which log-driven indicator best supports a hypothesis of compromised credentials rather than a misconfigured application?
Select an answer first - 25
Which of the following is a common Kubernetes attack vector that exploits overly permissive Role-Based Access Control (RBAC) permissions?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFR” is a trademark of its owner, used for identification only.