
GIAC Cloud Forensics Responder
Domain 5Objective 1
Understanding Microsoft Azure and Log Sources GCFR Practice Questions (Page 2)
Part of the Microsoft Azure Forensics domain, which makes up ~31% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~22–37 in this domain), expect 6–9 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
8concepts
Questions 6–10
- 6
A forensic investigator needs to analyze network traffic to and from a compromised Azure VM. Which Azure resource log should they enable to capture this data?
Select an answer first - 7
An investigator is analyzing a data breach. The Activity Log shows that a storage account's access keys were regenerated at 12:00 UTC. The resource logs for the storage account show a large download at 12:15 UTC. The investigator suspects that the attacker used the new access keys. Which additional evidence would BEST support this hypothesis?
Select an answer first - 8
Which Azure log source records control-plane operations such as creating, updating, or deleting resources, and is essential for tracking administrative actions?
Select an answer first - 9
A forensic investigator is examining a compromised Azure Kubernetes Service (AKS) cluster. They need to see the actions performed by the Kubernetes control plane, such as pod creation and deletion. Which log source should they enable?
Select an answer first - 10
An organization has resources spread across multiple Azure regions. A forensic investigator needs to collect Activity Logs for all resources in the 'westus' region for a specific time window. The resources are in different resource groups but within the same subscription. What is the most efficient way to collect the required logs?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFR” is a trademark of its owner, used for identification only.