Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Cloud Forensics Responder

Domain 5Objective 1

Understanding Microsoft Azure and Log Sources GCFR Practice Questions (Page 6)

Part of the Microsoft Azure Forensics domain, which makes up ~31% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~22–37 in this domain), expect 6–9 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)

42questions here
9free pages
8concepts

Questions 26–30

  1. 26expert · hard

    A forensic investigator is analyzing a breach where an attacker gained access to an Azure subscription. The investigator has the following logs: Azure AD sign-in logs showing a successful sign-in from an unusual IP at 14:32, Activity Logs showing a role assignment change at 14:35, and resource logs from a VM showing a data exfiltration at 14:40. The investigator needs to prove that the role assignment change was performed by the same user who signed in. Which approach is most effective?

    Select an answer first
  2. 27foundation · easy

    When reconstructing a timeline of events in Azure, which approach is most effective for correlating logs from different sources?

    Select an answer first
  3. 28expert · hard

    An investigator is reconstructing a timeline of an attack. They have the following logs: Azure AD sign-in logs show a user authenticated at 10:00 UTC. Activity Logs show a VM creation at 10:05 UTC. Resource logs for the VM show a suspicious process execution at 10:10 UTC. The investigator needs to determine the attacker's initial access vector. Which additional log source would provide the most useful information?

    Select an answer first
  4. 29foundation · easy

    Which Azure resource type is primarily used to store unstructured data such as virtual machine disks, logs, and backups, and can be a key source of forensic evidence?

    Select an answer first
  5. 30application · medium

    An organization is required to retain Azure Activity Logs and resource logs for 3 years for compliance. They currently have no diagnostic settings configured. What is the most efficient way to meet this requirement?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFR” is a trademark of its owner, used for identification only.