
GIAC Cloud Forensics Responder
Domain 2Objective 4
Log Sources for Google Cloud IR GCFR Practice Questions (Page 2)
Part of the Google Cloud Platform Forensics domain, which makes up ~26% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~18–31 in this domain), expect 5–8 from this objective — we provide 34 practice questions to prepare you well beyond it. (estimate)
34questions here
7free pages
9concepts
Questions 6–10
- 6
During an incident, you need to programmatically retrieve all log entries from a specific Compute Engine instance over the last hour. You have the instance's resource labels. Which Cloud Logging API call should you use?
Select an answer first - 7
During an incident response engagement in Google Cloud, you need to identify the primary log sources that provide visibility into user actions, resource changes, and system events. Which set of services represents the primary log sources for GCP incident response?
Select an answer first - 8
You need to find all log entries related to a specific Cloud Storage bucket in the Cloud Console. What is the most direct way to do this?
Select an answer first - 9
A forensic investigator is responding to an incident involving a compromised GKE cluster. Which GCP log source would provide the most direct evidence of actions performed by the Kubernetes control plane, such as creating a pod or modifying a deployment?
Select an answer first - 10
During an incident, you need to determine whether a user accessed a specific object in a Cloud Storage bucket. You have enabled Data Access audit logs, but you cannot find the relevant log entry. Which of the following is the most likely reason?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFR” is a trademark of its owner, used for identification only.