
GIAC Cloud Threat Detection
Domain 3Objective 3
Cloud Vulnerability Analysis GCTD Practice Questions (Page 4)
Part of the Cloud Threat Detection and Response domain, which makes up ~25% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 4–7 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)
45questions here
9free pages
8concepts
Questions 16–20
- 16
A security team discovers that an AWS IAM role used by a Lambda function has an overly permissive policy that allows 'iam:CreateUser' and 'iam:AttachUserPolicy'. The function only needs to read from an S3 bucket. What is the most appropriate remediation strategy?
Select an answer first - 17
Why is continuous vulnerability scanning important in cloud lifecycle management?
Select an answer first - 18
What is a key element of a clear vulnerability report for technical stakeholders?
Select an answer first - 19
A security team uses a third-party vulnerability scanner that reports a high number of false positives. The team is overwhelmed and is considering disabling the scanner. However, the compliance team requires continuous scanning. Which approach best addresses the situation?
Select an answer first - 20
A company uses a Kubernetes cluster on AWS (EKS) with a network load balancer exposing a management dashboard to the internet. The security team identifies that the dashboard has no authentication and is accessible to anyone. The team needs to remediate this quickly while minimizing downtime. Which action is the most appropriate first step?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCTD” is a trademark of its owner, used for identification only.