
GIAC Cloud Forensics Responder
Domain 4Objective 1
Understanding IR in AWS GCFR Practice Questions (Page 3)
Part of the Amazon Web Services Forensics domain, which makes up ~19% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~13–23 in this domain), expect 4–8 from this objective — we provide 23 practice questions to prepare you well beyond it. (estimate)
23questions here
5free pages
6concepts
Questions 11–15
- 11
Which AWS service can be used to analyze VPC Flow Logs to identify unusual network traffic patterns, such as large data exfiltration?
Select an answer first - 12
A small company is moving its infrastructure to AWS. The security team is developing an incident response plan. Which of the following is a key principle of incident response in the AWS cloud that the team should incorporate?
Select an answer first - 13
Which AWS feature provides a point-in-time, block-level copy of an Amazon EBS volume that can be used for forensic analysis?
Select an answer first - 14
A company has experienced a security incident involving an EC2 instance. The incident response team is designing a forensic investigation workflow. The team needs to ensure that the workflow includes steps for preserving evidence, analyzing data, and reporting findings. Which of the following is the MOST important consideration when designing the workflow?
Select an answer first - 15
When analyzing CloudTrail logs to reconstruct an incident, which of the following fields is most useful for identifying the source of an API call?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFR” is a trademark of its owner, used for identification only.