
GIAC Cloud Threat Detection
The GIAC Cloud Threat Detection (GCTD) certification validates your ability to detect and investigate suspicious activity in cloud infrastructure. It is designed for security professionals who monitor, detect, and respond to threats across AWS and Azure environments. Earning GCTD proves you can leverage cloud-native tools, third-party solutions, and custom automations to defend cloud services effectively.
575 practice questions · Updated 2026-07-30
4Domains
12Objectives
102Concepts
575Questions
GCTD Curriculum
Every domain, objective, and concept the GCTD exam measures.
- Cloud Monitoring Fundamentals
- Centralized Logging Architecture
- Log Ingestion Methods
- Log Storage and Retention
- Log Indexing and Search
- Log Correlation and Analysis
- Centralized Logging Security
- Network Monitoring Fundamentals
- Flow Monitoring Basics
- Cloud Network Traffic Sources
- Flow Log Configuration
- Flow Log Analysis
- Integration with Monitoring Tools
- Troubleshooting Flow Monitoring
- Host OS Monitoring Fundamentals
- Host Metrics Collection
- Host Log Monitoring
- Process and Service Monitoring
- File Integrity Monitoring
- Host-Based Intrusion Detection
- Integration with Cloud Monitoring Tools
- Alerting and Response
- Container Monitoring Fundamentals
- Container Runtime Monitoring
- Container Image Security Monitoring
- Container Orchestration Monitoring
- Kubernetes Control Plane Monitoring
- Kubernetes Workload Monitoring
- Container Network Monitoring
- Container Storage and Volume Monitoring
- Container Log Aggregation and Analysis
- Container Threat Detection Techniques
- Container Compliance and Policy Monitoring
- Container Incident Response and Forensics
- Data Storage Monitoring Fundamentals
- Cloud Storage Services Monitoring
- Database Monitoring
- Backup and Recovery Monitoring
- Data Access and Activity Monitoring
- Storage Security Monitoring
- Data Lifecycle and Compliance Monitoring
- Alerting and Incident Response for Storage
- Application Monitoring Fundamentals
- Proxy Monitoring Fundamentals
- Application Log Sources
- Proxy Log Sources
- Monitoring Application Performance and Security
- Monitoring Proxy Traffic and Security
- Correlating Application and Proxy Data
- Alerting and Response for Application and Proxy Threats
- Automated Detection Fundamentals
- Detection as Code
- Cloud-Native Detection Services
- Event Ingestion and Normalization
- Detection Rule Development
- Automated Response Orchestration
- Playbooks and Runbooks
- Integration with SOAR
- Testing and Validation
- Monitoring and Metrics
- Cloud CTI Fundamentals
- Cloud Threat Actors and Motivations
- Cloud Threat Landscape
- CTI Sources and Feeds
- Threat Intelligence Lifecycle
- Indicators of Compromise (IOCs) in Cloud
- Tactics, Techniques, and Procedures (TTPs)
- CTI Integration with Cloud Detection
- Threat Intelligence Sharing and Collaboration
- CTI for Cloud Incident Response
- Cloud Vulnerability Identification
- Cloud Vulnerability Assessment Methodologies
- Cloud-Specific Vulnerability Scanning
- Cloud Misconfiguration Analysis
- Cloud Vulnerability Prioritization
- Cloud Vulnerability Remediation Strategies
- Cloud Vulnerability Reporting
- Cloud Vulnerability Lifecycle Management
- AWS CloudTrail log analysis
- AWS VPC Flow Logs analysis
- AWS GuardDuty findings interpretation
- AWS Config resource tracking
- AWS IAM policy and role investigation
- AWS S3 access log analysis
- AWS CloudWatch log insights
- AWS Security Hub aggregation
- AWS EC2 instance forensics
- AWS Lambda function investigation
- Azure Resource Inventory
- Azure Activity Log Analysis
- Azure Resource Log Analysis
- Azure AD Sign-in and Audit Logs
- Azure Threat Detection Services
- Azure Network Traffic Analysis
- Azure Storage and Data Access Investigation
- Azure Role-Based Access Control (RBAC) Review
- Azure Resource Manager (ARM) Template Analysis
- Azure VM and Disk Forensics
- Azure Kubernetes Service (AKS) Investigation
- Azure Key Vault and Secrets Monitoring
- Azure Policy and Compliance Checks
- Azure Cross-Tenant and Hybrid Investigation
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.
Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for GCTD, so none is invented.