Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Cloud Security Essentials

Domain 6Objective 1

Cloud Logging Fundamentals GCLD Practice Questions (Page 2)

Part of the Logging and Incident Response domain, which makes up ~10% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~5–8 in this domain), expect 3–4 from this objective — we provide 36 practice questions to prepare you well beyond it. (estimate)

36questions here
8free pages
1concept

Questions 6–10

  1. 6application · medium

    A company is required to retain logs for a minimum of one year for compliance. They are using a cloud logging service that stores logs in a storage bucket. What is the most important consideration for meeting this requirement?

    Select an answer first
  2. 7foundation · easy

    Which of the following is a core component of cloud logging that represents the origin of log data, such as a virtual machine, container, or cloud service?

    Select an answer first
  3. 8application · medium

    A security analyst needs to reconstruct the sequence of actions taken by a compromised user account during a 48-hour period. The cloud environment uses a centralized logging pipeline that ingests authentication logs, API call logs, and virtual machine guest OS logs. Which combination of log types is essential for this reconstruction?

    Select an answer first
  4. 9expert · hard

    A security analyst is investigating a potential insider threat. The analyst has access to authentication logs, file access logs, and email logs. The analyst needs to determine whether a user accessed sensitive files and then sent them externally. Which combination of logs is essential for this investigation?

    Select an answer first
  5. 10application · medium

    A security analyst is investigating a suspected brute-force attack against a web application. The application runs on a single virtual machine and writes authentication failures to a local log file. The analyst needs to correlate these failures with network-level connection attempts and user account activity. Which combination of log sources should the analyst prioritize?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCLD” is a trademark of its owner, used for identification only.