
GIAC Cloud Security Essentials
Domain 2Objective 3
Network Security Monitoring in the Cloud GCLD Practice Questions (Page 5)
Part of the Cloud Networking and Security domain, which makes up ~16% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–13 in this domain), expect 3–4 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)
43questions here
9free pages
5concepts
Questions 21–25
- 21
When configuring an alert for suspicious activity in a cloud network, which element is essential for the alert to be useful?
Select an answer first - 22
Which technique is commonly used to detect network anomalies in cloud environments by establishing a baseline of normal behavior?
Select an answer first - 23
During an incident response in a cloud environment, which data source is most useful for reconstructing the sequence of network connections made by a compromised instance?
Select an answer first - 24
A security analyst is configuring alerts for a cloud environment. They want to detect port scanning activity. They have VPC Flow Logs enabled and a SIEM. Which detection method would be most effective?
Select an answer first - 25
During a forensic investigation in AWS, an analyst needs to prove that a specific EC2 instance communicated with a known malicious IP at a specific time. Which data source would provide the most reliable evidence?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCLD” is a trademark of its owner, used for identification only.