Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Cloud Forensics Responder

Domain 2Objective 4

Log Sources for Google Cloud IR GCFR Practice Questions (Page 1)

Part of the Google Cloud Platform Forensics domain, which makes up ~26% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~18–31 in this domain), expect 5–8 from this objective — we provide 34 practice questions to prepare you well beyond it. (estimate)

34questions here
7free pages
9concepts

Questions 1–5

  1. 1application · medium

    You are investigating a suspicious API call that created a new Cloud Storage bucket. In the log entry, you need to identify which specific bucket was created. Which field in the log entry should you examine?

    Select an answer first
  2. 2foundation · easy

    Which type of Cloud Audit Log records actions performed by administrators or other authorized users that modify the configuration or metadata of GCP resources?

    Select an answer first
  3. 3application · medium

    A responder is using the Cloud Logging API to retrieve logs for a specific Cloud Storage bucket. Which field in the log entry should be used to filter for that bucket?

    Select an answer first
  4. 4foundation · easy

    You are investigating a compromised Compute Engine instance. Which field in the log entry would you use to filter for logs specifically from that instance?

    Select an answer first
  5. 5foundation · easy

    Which Cloud Storage feature can help ensure log integrity by preventing modification or deletion of log objects after they are written?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFR” is a trademark of its owner, used for identification only.