Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Cloud Forensics Responder

Domain 5Objective 1

Understanding Microsoft Azure and Log Sources GCFR Practice Questions (Page 1)

Part of the Microsoft Azure Forensics domain, which makes up ~31% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~22–37 in this domain), expect 6–9 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)

42questions here
9free pages
8concepts

Questions 1–5

  1. 1foundation · easy

    Which Azure AD log type records successful and failed sign-in attempts, including the user, application, IP address, and sign-in status?

    Select an answer first
  2. 2application · medium

    A forensic investigator is analyzing a suspected unauthorized deletion of a virtual machine in Azure. The VM was in the 'prod-eastus' resource group within the 'ContosoProd' subscription. The investigator needs to determine who initiated the delete operation and when it occurred. Which log source should the investigator query first?

    Select an answer first
  3. 3application · medium

    A web application running on Azure App Service is suspected of being compromised. The investigator needs to see the application's runtime logs, including HTTP requests and errors. Which log source should they enable?

    Select an answer first
  4. 4expert · hard

    A forensic investigator is analyzing a data breach in an Azure environment. The investigator has resource logs from a compromised VM showing outbound network connections to a suspicious IP. The investigator also has Activity Logs showing that a network security group (NSG) was modified to allow outbound traffic just before the connections occurred. The investigator needs to establish the sequence of events. Which approach is most reliable?

    Select an answer first
  5. 5application · medium

    A company is troubleshooting a performance issue on an Azure VM. The investigator needs to see CPU and memory usage over time. Which Azure log or metric should they use?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFR” is a trademark of its owner, used for identification only.