
GIAC Cloud Forensics Responder
Domain 5Objective 2
Microsoft Azure Virtual Machines GCFR Practice Questions (Page 2)
Part of the Microsoft Azure Forensics domain, which makes up ~31% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~22–37 in this domain), expect 6–9 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)
43questions here
9free pages
10concepts
Questions 6–10
- 6
Which Azure VM extension is commonly used to collect diagnostic data from a Windows VM, including performance counters and event logs, for forensic analysis?
Select an answer first - 7
Which Azure component provides the virtualized compute capacity for an Azure Virtual Machine and is the primary target for forensic memory acquisition?
Select an answer first - 8
Which Azure feature creates a point-in-time, read-only copy of a VM's disk that can be used to create a new disk for forensic analysis without affecting the original?
Select an answer first - 9
Which Azure service provides a centralized platform for collecting and analyzing metrics and logs from Azure VMs, which can be used to correlate forensic evidence?
Select an answer first - 10
An incident responder is analyzing an Azure VM that was part of a botnet. The VM has been deallocated, and the responder needs to determine the VM's private IP address at the time of the incident. The VM's NIC is still present. Which Azure resource should they examine to find the private IP address?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFR” is a trademark of its owner, used for identification only.