
GIAC Cloud Threat Detection
Domain 2Objective 2
Containers and Orchestration GCTD Practice Questions (Page 10)
Part of the Cloud Infrastructure Monitoring domain, which makes up ~37% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~19–30 in this domain), expect 5–8 from this objective — we provide 59 practice questions to prepare you well beyond it. (estimate)
59questions here
12free pages
12concepts
Questions 46–50
- 46
A Kubernetes administrator wants to detect unauthorized changes to cluster roles and role bindings. Which monitoring data should be collected and analyzed?
Select an answer first - 47
Which forensic artifact is most important to preserve from a compromised container?
Select an answer first - 48
A security operations center (SOC) wants to centralize logs from multiple Kubernetes clusters, including API server audit logs, kubelet logs, and container stdout/stderr. The solution must support correlation across clusters and provide near-real-time alerting. Which approach best meets these requirements?
Select an answer first - 49
A security auditor requires that all container images used in production have a signed provenance and are free of critical vulnerabilities. The team needs to enforce this at deployment time. Which combination of tools should they implement?
Select an answer first - 50
A security team is investigating a possible data exfiltration from a containerized application. The application mounts a persistent volume that contains sensitive files. Which monitoring approach would best detect unauthorized reads from the volume?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCTD” is a trademark of its owner, used for identification only.