
GIAC Cloud Forensics Responder
Domain 5Objective 1
Understanding Microsoft Azure and Log Sources GCFR Practice Questions (Page 9)
Part of the Microsoft Azure Forensics domain, which makes up ~31% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~22–37 in this domain), expect 6–9 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
8concepts
Questions 41–42
- 41
An organization wants to have a complete audit trail of all administrative actions in Azure, including who created, modified, or deleted resources, and when. Which log source should they rely on?
Select an answer first - 42
An investigator is analyzing a phishing attack that led to a user's account being compromised. The attacker used the compromised account to access Azure resources. Which Azure AD log would show the attacker's IP address and the application used?
Select an answer first
Finished these 2 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GCFR
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFR” is a trademark of its owner, used for identification only.