
GIAC Cloud Security Essentials
Domain 2Objective 3
Network Security Monitoring in the Cloud GCLD Practice Questions (Page 8)
Part of the Cloud Networking and Security domain, which makes up ~16% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–13 in this domain), expect 3–4 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)
43questions here
9free pages
5concepts
Questions 36–40
- 36
A security team is planning to implement network monitoring in a new cloud environment. They are concerned about the shared responsibility model and want to ensure they have visibility into all layers of the network stack. Which approach best addresses this concern?
Select an answer first - 37
During an incident response, a forensic investigator needs to determine which internal hosts communicated with a known malicious external IP over the past 30 days. The company uses AWS and has VPC Flow Logs enabled. What is the most efficient way to obtain this information?
Select an answer first - 38
A company uses Azure and wants to detect data exfiltration attempts from a VM to an external IP. They have NSG flow logs enabled and Azure Sentinel. Which configuration would best detect this?
Select an answer first - 39
A security team wants to receive alerts when a specific IAM role is used to make API calls from an unusual geographic location. They have enabled CloudTrail in AWS and are sending logs to a SIEM. What is the best way to configure this alert?
Select an answer first - 40
What is the primary purpose of integrating cloud network monitoring data into a SIEM platform?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCLD” is a trademark of its owner, used for identification only.