Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Cloud Security Essentials

Domain 6Objective 2

Attacking the Cloud and Responding to Intrusions GCLD Practice Questions (Page 4)

Part of the Logging and Incident Response domain, which makes up ~10% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~5–8 in this domain), expect 3–4 from this objective — we provide 30 practice questions to prepare you well beyond it. (estimate)

30questions here
6free pages
6concepts

Questions 16–20

  1. 16application · medium

    A security analyst is reviewing Azure AD sign-in logs and sees a user account successfully authenticating from a new IP address in a different country at 2:00 AM, followed by a failed attempt to access a sensitive SharePoint site. The user is currently on vacation. Which set of actions should the analyst take to confirm a possible account compromise and limit damage?

    Select an answer first
  2. 17application · medium

    A forensic investigator needs to collect evidence from a compromised virtual machine running in a public cloud. The VM is still running and the attacker may have a live connection. Which evidence collection method is most likely to preserve the integrity of the evidence?

    Select an answer first
  3. 18foundation · easy

    Which of the following activities would be considered a suspicious activity that should be investigated in cloud logs?

    Select an answer first
  4. 19application · medium

    A company stores customer PII in an S3 bucket that is accessed by a legacy application. The security team notices a spike in GET requests from an external IP that is not on the allowlist, and the requests are returning HTTP 200. The bucket policy currently allows public read access to a prefix that should only be accessible by the application. Which action should the team take FIRST to stop the unauthorized access while preserving evidence?

    Select an answer first
  5. 20expert · medium

    A security analyst is monitoring a cloud environment and notices that a large number of failed login attempts are occurring against a cloud application. The attempts are coming from a single IP address. Which of the following is the BEST action to take?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCLD” is a trademark of its owner, used for identification only.