Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Cloud Forensics Responder

Domain 6Objective 1

Kubernetes Overview, Logs, and Common Attacks GCFR Practice Questions (Page 5)

Part of the Kubernetes Forensics domain, which makes up ~6% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~4–7 in this domain), expect 4–7 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)

32questions here
7free pages
6concepts

Questions 21–25

  1. 21foundation · easy

    Which Kubernetes log source would you examine to detect an attacker creating a new Pod with a privileged container?

    Select an answer first
  2. 22application · medium

    A forensics team needs to collect logs from a Kubernetes cluster where applications write logs to stdout, but the team also needs to capture logs from a legacy application that writes only to a file inside its container. The cluster does not have a node-level logging agent deployed. Which approach ensures both log sources are collected without modifying the application?

    Select an answer first
  3. 23application · medium

    A Kubernetes cluster uses a centralized logging solution that collects logs from all namespaces. The security team wants to ensure that logs from the kube-system namespace are retained for a longer period than other namespaces due to compliance requirements. Which approach should they take?

    Select an answer first
  4. 24application · medium

    A SOC analyst is reviewing Kubernetes audit logs and notices a series of API calls from a single service account that suddenly begins creating pods with hostPID: true and mounting the host filesystem. The account had no prior history of creating pods. Which log-driven indicator best supports a hypothesis of compromised credentials rather than a misconfigured application?

    Select an answer first
  5. 25foundation · easy

    Which of the following is a common Kubernetes attack vector that exploits overly permissive Role-Based Access Control (RBAC) permissions?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFR” is a trademark of its owner, used for identification only.