
GIAC Cloud Forensics Responder
Domain 4Objective 1
Understanding IR in AWS GCFR Practice Questions (Page 1)
Part of the Amazon Web Services Forensics domain, which makes up ~19% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~13–23 in this domain), expect 4–8 from this objective — we provide 23 practice questions to prepare you well beyond it. (estimate)
23questions here
5free pages
6concepts
Questions 1–5
- 1
During an investigation, you have CloudTrail logs showing that an IAM role was used to launch a new EC2 instance. You also have VPC Flow Logs showing traffic to an unknown IP address from that instance. Which analysis technique would best help you determine if the instance was used for data exfiltration?
Select an answer first - 2
A security team is preparing for incident response in AWS. They want to ensure that they have the necessary forensic data sources available. Which of the following is a BEST PRACTICE for preparing for incident response in AWS?
Select an answer first - 3
In a structured AWS forensic investigation workflow, which step typically follows the collection of forensic artifacts?
Select an answer first - 4
When investigating a security incident in AWS, which of the following forensic data sources is AWS responsible for providing, according to the shared responsibility model?
Select an answer first - 5
Which method is commonly used to collect a non-volatile forensic artifact from an Amazon EBS volume without altering the original volume?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFR” is a trademark of its owner, used for identification only.