Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS)

GIAC Cloud Threat Detection

GCTDGIAC Cloud Threat Detection (GCTD)

The GIAC Cloud Threat Detection (GCTD) certification validates your ability to detect and investigate suspicious activity in cloud infrastructure. It is designed for security professionals who monitor, detect, and respond to threats across AWS and Azure environments. Earning GCTD proves you can leverage cloud-native tools, third-party solutions, and custom automations to defend cloud services effectively.

575 practice questions · Updated 2026-07-30

4Domains
12Objectives
102Concepts
575Questions

GCTD Curriculum

Every domain, objective, and concept the GCTD exam measures.

Cloud Monitoring Fundamentals

1 concepts · 30 questions
  1. Cloud Monitoring Fundamentals

Log Centralization

6 concepts · 46 questions
  1. Centralized Logging Architecture
  2. Log Ingestion Methods
  3. Log Storage and Retention
  4. Log Indexing and Search
  5. Log Correlation and Analysis
  6. Centralized Logging Security

Network and Flow Monitoring

7 concepts · 40 questions
  1. Network Monitoring Fundamentals
  2. Flow Monitoring Basics
  3. Cloud Network Traffic Sources
  4. Flow Log Configuration
  5. Flow Log Analysis
  6. Integration with Monitoring Tools
  7. Troubleshooting Flow Monitoring

Host OS Monitoring

8 concepts · 51 questions
  1. Host OS Monitoring Fundamentals
  2. Host Metrics Collection
  3. Host Log Monitoring
  4. Process and Service Monitoring
  5. File Integrity Monitoring
  6. Host-Based Intrusion Detection
  7. Integration with Cloud Monitoring Tools
  8. Alerting and Response

Containers and Orchestration

12 concepts · 59 questions
  1. Container Monitoring Fundamentals
  2. Container Runtime Monitoring
  3. Container Image Security Monitoring
  4. Container Orchestration Monitoring
  5. Kubernetes Control Plane Monitoring
  6. Kubernetes Workload Monitoring
  7. Container Network Monitoring
  8. Container Storage and Volume Monitoring
  9. Container Log Aggregation and Analysis
  10. Container Threat Detection Techniques
  11. Container Compliance and Policy Monitoring
  12. Container Incident Response and Forensics

Data and Storage Monitoring

8 concepts · 53 questions
  1. Data Storage Monitoring Fundamentals
  2. Cloud Storage Services Monitoring
  3. Database Monitoring
  4. Backup and Recovery Monitoring
  5. Data Access and Activity Monitoring
  6. Storage Security Monitoring
  7. Data Lifecycle and Compliance Monitoring
  8. Alerting and Incident Response for Storage

Application and Proxy Monitoring

8 concepts · 47 questions
  1. Application Monitoring Fundamentals
  2. Proxy Monitoring Fundamentals
  3. Application Log Sources
  4. Proxy Log Sources
  5. Monitoring Application Performance and Security
  6. Monitoring Proxy Traffic and Security
  7. Correlating Application and Proxy Data
  8. Alerting and Response for Application and Proxy Threats

Automated Detection and Response

10 concepts · 43 questions
  1. Automated Detection Fundamentals
  2. Detection as Code
  3. Cloud-Native Detection Services
  4. Event Ingestion and Normalization
  5. Detection Rule Development
  6. Automated Response Orchestration
  7. Playbooks and Runbooks
  8. Integration with SOAR
  9. Testing and Validation
  10. Monitoring and Metrics

Cyber Threat Intelligence for the Cloud

10 concepts · 58 questions
  1. Cloud CTI Fundamentals
  2. Cloud Threat Actors and Motivations
  3. Cloud Threat Landscape
  4. CTI Sources and Feeds
  5. Threat Intelligence Lifecycle
  6. Indicators of Compromise (IOCs) in Cloud
  7. Tactics, Techniques, and Procedures (TTPs)
  8. CTI Integration with Cloud Detection
  9. Threat Intelligence Sharing and Collaboration
  10. CTI for Cloud Incident Response

Cloud Vulnerability Analysis

8 concepts · 45 questions
  1. Cloud Vulnerability Identification
  2. Cloud Vulnerability Assessment Methodologies
  3. Cloud-Specific Vulnerability Scanning
  4. Cloud Misconfiguration Analysis
  5. Cloud Vulnerability Prioritization
  6. Cloud Vulnerability Remediation Strategies
  7. Cloud Vulnerability Reporting
  8. Cloud Vulnerability Lifecycle Management

Investigating AWS Environments

10 concepts · 48 questions
  1. AWS CloudTrail log analysis
  2. AWS VPC Flow Logs analysis
  3. AWS GuardDuty findings interpretation
  4. AWS Config resource tracking
  5. AWS IAM policy and role investigation
  6. AWS S3 access log analysis
  7. AWS CloudWatch log insights
  8. AWS Security Hub aggregation
  9. AWS EC2 instance forensics
  10. AWS Lambda function investigation

Investigating Azure Environments

14 concepts · 55 questions
  1. Azure Resource Inventory
  2. Azure Activity Log Analysis
  3. Azure Resource Log Analysis
  4. Azure AD Sign-in and Audit Logs
  5. Azure Threat Detection Services
  6. Azure Network Traffic Analysis
  7. Azure Storage and Data Access Investigation
  8. Azure Role-Based Access Control (RBAC) Review
  9. Azure Resource Manager (ARM) Template Analysis
  10. Azure VM and Disk Forensics
  11. Azure Kubernetes Service (AKS) Investigation
  12. Azure Key Vault and Secrets Monitoring
  13. Azure Policy and Compliance Checks
  14. Azure Cross-Tenant and Hybrid Investigation
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.

Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for GCTD, so none is invented.