
GIAC Cloud Forensics Responder
Domain 2Objective 4
Log Sources for Google Cloud IR GCFR Practice Questions (Page 4)
Part of the Google Cloud Platform Forensics domain, which makes up ~26% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~18–31 in this domain), expect 5–8 from this objective — we provide 34 practice questions to prepare you well beyond it. (estimate)
34questions here
7free pages
9concepts
Questions 16–20
- 16
A security engineer is building a tool to automatically detect suspicious activity by querying Cloud Logging. The tool needs to retrieve logs from multiple projects and aggregate them. Which approach is most efficient and scalable?
Select an answer first - 17
What is the default retention period for logs stored in Cloud Logging?
Select an answer first - 18
An analyst is investigating a compromised Compute Engine instance. The analyst wants to see all logs related to that instance, including system logs and audit logs. In the Logs Explorer, which filter would be most effective?
Select an answer first - 19
You need to export logs to Cloud Storage for long-term retention. Which destination type can be used in a log sink?
Select an answer first - 20
What is the name of the Cloud Logging feature that allows you to route log entries to destinations like BigQuery, Pub/Sub, or Cloud Storage?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFR” is a trademark of its owner, used for identification only.