
GIAC Cloud Threat Detection
Domain 3Objective 3
Cloud Vulnerability Analysis GCTD Practice Questions (Page 2)
Part of the Cloud Threat Detection and Response domain, which makes up ~25% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 4–7 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)
45questions here
9free pages
8concepts
Questions 6–10
- 6
A security engineer is assessing a cloud environment and finds that a serverless function has an overly permissive IAM role that allows it to invoke any other function in the account. The function is publicly accessible via an API gateway. What is the most significant risk?
Select an answer first - 7
Which remediation strategy is most appropriate for a cloud misconfiguration that exposes a management console to the internet?
Select an answer first - 8
Which of the following is a common cloud vulnerability that arises when a cloud storage bucket is configured to allow public read access to sensitive data?
Select an answer first - 9
Which cloud-native service is designed to scan serverless functions for vulnerabilities and misconfigurations?
Select an answer first - 10
A security team discovers that an Azure VM has a critical vulnerability in the operating system. The VM is part of a production application and cannot be rebooted during business hours. What is the most appropriate remediation strategy?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCTD” is a trademark of its owner, used for identification only.