Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Cloud Forensics Responder

Domain 6Objective 1

Kubernetes Overview, Logs, and Common Attacks GCFR Practice Questions (Page 7)

Part of the Kubernetes Forensics domain, which makes up ~6% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~4–7 in this domain), expect 4–7 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)

32questions here
7free pages
6concepts

Questions 31–32

  1. 31application · medium

    A security analyst is investigating a suspected data exfiltration from a Kubernetes cluster. The analyst needs to determine what commands were executed inside a specific container. Which log source should the analyst examine?

    Select an answer first
  2. 32application · medium

    A responder is analyzing kube-apiserver audit logs and sees a series of requests from a user account that include 'get', 'list', and 'watch' verbs on the 'secrets' resource across multiple namespaces. The user's role is defined as 'view' which should only allow read access to non-sensitive resources. What does this log pattern most likely indicate?

    Select an answer first
Finished these 2 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to GCFR

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFR” is a trademark of its owner, used for identification only.