
GIAC Cloud Threat Detection
Domain 3Objective 1
Automated Detection and Response GCTD Practice Questions (Page 9)
Part of the Cloud Threat Detection and Response domain, which makes up ~25% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 4–7 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)
43questions here
9free pages
10concepts
Questions 41–43
- 41
A company is ingesting logs from AWS CloudTrail, Azure Active Directory, and Google Workspace into a central SIEM. The security team wants to write detection rules that can query across all three sources using a common schema. Which approach is most effective?
Select an answer first - 42
Which practice is essential for implementing detection as code?
Select an answer first - 43
A company uses Azure Sentinel and wants to ingest AWS CloudTrail logs. The logs are stored in an S3 bucket. Which method should they use to get the logs into Sentinel for analysis?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GCTD
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCTD” is a trademark of its owner, used for identification only.