
GIAC Cyber Incident Leader
Domain 1Objective 1
Cloud Attacks GCIL Practice Questions (Page 4)
Part of the Attack Types and Vectors domain, which makes up ~33% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~17–26 in this domain), expect 3–5 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)
43questions here
9free pages
5concepts
Questions 16–20
- 16
An organization's cloud environment is compromised. The attacker used a stolen API key to create a new administrative user and then used that user to exfiltrate data from a database. Which sequence of events BEST describes the attack?
Select an answer first - 17
During a cloud incident, the incident response team needs to preserve evidence. Which action is MOST appropriate for preserving forensic evidence in a cloud environment?
Select an answer first - 18
A cloud account's access keys were compromised, and the attacker created new administrative users and modified network security groups. Which cloud-specific attack technique does this describe?
Select an answer first - 19
A company is using a cloud provider's serverless function service (e.g., AWS Lambda) to process sensitive data. The security team wants to ensure that the function can only access a specific database and no other cloud resources. Which control should they implement?
Select an answer first - 20
During an incident investigation, a security analyst needs to determine if a compromised cloud account was used to exfiltrate data from a storage service. Which data source would provide the MOST direct evidence of data exfiltration?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIL” is a trademark of its owner, used for identification only.