
GIAC Cloud Threat Detection
Domain 3Objective 1
Automated Detection and Response GCTD Practice Questions (Page 3)
Part of the Cloud Threat Detection and Response domain, which makes up ~25% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 4–7 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)
43questions here
9free pages
10concepts
Questions 11–15
- 11
A SOC manager wants to measure the effectiveness of automated response playbooks. They need a metric that reflects how quickly the team contains a threat after an alert is generated. Which metric best captures this?
Select an answer first - 12
Which metric is used to measure the effectiveness of automated detection?
Select an answer first - 13
A security team has deployed a new detection rule that flags suspicious PowerShell activity. They want to validate that the rule fires on actual malicious behavior and does not generate excessive noise. Which method is most appropriate?
Select an answer first - 14
A company uses multiple cloud services and wants to centralize logs for threat detection. They have a mix of structured logs (e.g., CloudTrail) and unstructured logs (e.g., application logs). They need to ensure that the detection platform can query both types effectively. Which approach is best?
Select an answer first - 15
Which action is commonly automated in response orchestration?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCTD” is a trademark of its owner, used for identification only.