Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Cloud Threat Detection

Domain 3Objective 3

Cloud Vulnerability Analysis GCTD Practice Questions (Page 9)

Part of the Cloud Threat Detection and Response domain, which makes up ~25% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 4–7 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)

45questions here
9free pages
8concepts

Questions 41–45

  1. 41application · medium

    A vulnerability scan of a cloud environment identifies the following issues: (1) an S3 bucket with public read access containing non-sensitive marketing files, (2) a critical RCE vulnerability in a public-facing web application, (3) an IAM user with an unused admin access key, and (4) a database with a weak password. The security team has limited resources and must prioritize remediation. Which vulnerability should be addressed first?

    Select an answer first
  2. 42expert · hard

    A security team is assessing a hybrid cloud environment with on-premises data centers and AWS. They need to use a methodology that covers both cloud and on-premises components and aligns with industry standards. Which approach is most appropriate?

    Select an answer first
  3. 43expert · hard

    A company runs a critical application on AWS EC2 instances behind an Application Load Balancer. A vulnerability scan reveals that the EC2 instances have a critical kernel vulnerability that requires a reboot to patch. The application is stateful and cannot tolerate downtime. The security team must remediate the vulnerability with minimal disruption. Which strategy is most appropriate?

    Select an answer first
  4. 44foundation · easy

    What is the final step in the cloud vulnerability lifecycle?

    Select an answer first
  5. 45application · medium

    A DevOps team uses Azure Container Instances (ACI) to run a batch processing job. A vulnerability scan of the container image reports a critical vulnerability in a shared library. The team needs to remediate the vulnerability before the next scheduled run. Which approach is the most effective?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to GCTD

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCTD” is a trademark of its owner, used for identification only.