
GIAC Cloud Security Essentials
Domain 2Objective 3
Network Security Monitoring in the Cloud GCLD Practice Questions (Page 9)
Part of the Cloud Networking and Security domain, which makes up ~16% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–13 in this domain), expect 3–4 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)
43questions here
9free pages
5concepts
Questions 41–43
- 41
A company uses a multi-cloud environment with workloads in AWS and Azure. The security team wants a centralized view of network traffic across both clouds and the ability to correlate anomalies. Which approach best meets this requirement?
Select an answer first - 42
A cloud security team wants to detect anomalous outbound traffic from a Kubernetes cluster. They have enabled flow logs for the VPC and are sending them to a SIEM. Which configuration would best enable the detection of a compromised pod that is beaconing to an external IP?
Select an answer first - 43
A company uses GCP and has VPC Flow Logs enabled. They are experiencing a high volume of false positives from their anomaly detection system, which alerts on any new external IP connection. The security team wants to reduce false positives while still detecting real threats. Which approach is most effective?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GCLD
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCLD” is a trademark of its owner, used for identification only.