
GIAC Cloud Forensics Responder
Domain 5Objective 1
Understanding Microsoft Azure and Log Sources GCFR Practice Questions (Page 8)
Part of the Microsoft Azure Forensics domain, which makes up ~31% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~22–37 in this domain), expect 6–9 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
8concepts
Questions 36–40
- 36
Which Azure resource type is most likely to contain forensic artifacts such as OS files, user activity logs, and memory dumps from a compromised system?
Select an answer first - 37
Which Azure concept is most important for a forensic investigator to document because it determines the physical location of a resource and thus the applicable data residency and legal jurisdiction?
Select an answer first - 38
A company has a compliance requirement to retain Azure Activity Logs for 7 years. They currently stream Activity Logs to a Log Analytics workspace with a 90-day retention policy. They also export to an Azure Storage account. The investigator needs to access logs from 2 years ago. What is the most likely way to retrieve those logs?
Select an answer first - 39
An organization is investigating a suspicious deletion of a storage account. The Activity Log shows the deletion was performed by a user account, but the user denies any involvement. The investigator needs to determine if the user's credentials were compromised. Which additional log source would provide the most useful evidence?
Select an answer first - 40
What is the default retention period for Azure Activity Logs in the Azure portal?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFR” is a trademark of its owner, used for identification only.