
GIAC Cloud Forensics Responder
Domain 5Objective 4
Microsoft Unified Audit Log and Graph API GCFR Practice Questions (Page 3)
Part of the Microsoft Azure Forensics domain, which makes up ~31% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~22–37 in this domain), expect 6–9 from this objective — we provide 41 practice questions to prepare you well beyond it. (estimate)
41questions here
9free pages
9concepts
Questions 11–15
- 11
When querying the Microsoft Graph API for audit logs, what does the '$filter' query parameter do?
Select an answer first - 12
A small business is using Microsoft 365 Business Standard and wants to enable auditing for their tenant. They are unsure where to enable it. Which portal should they use to turn on the Unified Audit Log?
Select an answer first - 13
An analyst is investigating a suspicious administrative action in Azure AD. The Unified Audit Log shows that a user with the role of Global Administrator added a new user. The Azure AD sign-in log shows a successful sign-in from an IP address that is not in the company's allowed locations. The analyst needs to determine if the action was performed by the legitimate administrator or by an attacker who compromised the account. Which combination of data sources would provide the most comprehensive evidence to make this determination?
Select an answer first - 14
Which OAuth 2.0 grant type is commonly used by a daemon application to authenticate to Microsoft Graph API?
Select an answer first - 15
Which additional data source is commonly correlated with Unified Audit Log entries to gain insight into authentication events?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFR” is a trademark of its owner, used for identification only.