
GIAC Cloud Threat Detection
Domain 2Objective 2
Containers and Orchestration GCTD Practice Questions (Page 12)
Part of the Cloud Infrastructure Monitoring domain, which makes up ~37% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~19–30 in this domain), expect 5–8 from this objective — we provide 59 practice questions to prepare you well beyond it. (estimate)
59questions here
12free pages
12concepts
Questions 56–59
- 56
What is the primary focus of container orchestration monitoring?
Select an answer first - 57
A security team wants to detect lateral movement between pods in a Kubernetes cluster. They have enabled network policy but want to monitor for connections that bypass the intended policy. Which monitoring data would be most effective?
Select an answer first - 58
A security analyst is reviewing container image pulls from a private registry and notices that a specific image tag has been pulled repeatedly over a short period from different IP addresses. The image is a base image that is rarely updated. What should the analyst do first?
Select an answer first - 59
A security team needs to monitor a Kubernetes persistent volume that is shared by multiple pods. They want to detect if any pod writes to a file that should be read-only. Which approach is most effective?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GCTD
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCTD” is a trademark of its owner, used for identification only.