
GIAC Cyber Incident Leader
Domain 1Objective 1
Cloud Attacks GCIL Practice Questions (Page 3)
Part of the Attack Types and Vectors domain, which makes up ~33% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~17–26 in this domain), expect 3–5 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)
43questions here
9free pages
5concepts
Questions 11–15
- 11
A cloud incident has been contained. The incident response team needs to conduct a forensic investigation. Which action is MOST important for preserving the integrity of the evidence?
Select an answer first - 12
A company uses a cloud provider's IaaS to run a web server. The security team wants to detect and respond to a potential brute-force attack on the server's SSH service. Which control is most appropriate?
Select an answer first - 13
A company is migrating a legacy customer-facing application to the cloud. The application runs on a managed Kubernetes service (PaaS) and uses a cloud-managed relational database. The security team must respond to a suspected data breach. Which of the following responsibilities remains with the customer under the shared responsibility model?
Select an answer first - 14
Which of the following is a common attack vector targeting cloud environments that involves the use of stolen or leaked authentication information?
Select an answer first - 15
When responding to a cloud incident, why is it important to preserve forensic evidence such as snapshots and logs?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIL” is a trademark of its owner, used for identification only.