
GIAC Cloud Forensics Responder
Domain 2Objective 4
Log Sources for Google Cloud IR GCFR Practice Questions (Page 6)
Part of the Google Cloud Platform Forensics domain, which makes up ~26% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~18–31 in this domain), expect 5–8 from this objective — we provide 34 practice questions to prepare you well beyond it. (estimate)
34questions here
7free pages
9concepts
Questions 26–30
- 26
Which Cloud Logging API method is used to programmatically retrieve log entries from Cloud Logging?
Select an answer first - 27
A forensic investigator needs to determine if an attacker accessed a specific Cloud Storage object. Which combination of log sources would provide the most relevant evidence?
Select an answer first - 28
You are designing a log integrity solution for a highly regulated environment. You need to ensure that logs cannot be altered or deleted by an attacker who gains access to your GCP project. You also need to maintain the ability to analyze logs in real time. Which solution best meets these requirements?
Select an answer first - 29
An organization wants to stream real-time Cloud Logging entries to an external SIEM for immediate alerting. Which log sink destination should be configured?
Select an answer first - 30
A developer is writing a script to retrieve all logs from a specific time range for a project. The script uses the Cloud Logging API. Which parameter is required to filter by time?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFR” is a trademark of its owner, used for identification only.