Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Cloud Threat Detection

Domain 3Objective 2

Cyber Threat Intelligence for the Cloud GCTD Practice Questions (Page 7)

Part of the Cloud Threat Detection and Response domain, which makes up ~25% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 4–7 from this objective — we provide 58 practice questions to prepare you well beyond it. (estimate)

58questions here
12free pages
10concepts

Questions 31–35

  1. 31foundation · easy

    Which of the following is a common method for integrating CTI into a SIEM for cloud detection?

    Select an answer first
  2. 32application · medium

    A security manager is explaining the value of CTI to the executive team after a cloud security incident. The incident involved a misconfigured database that was publicly accessible. The manager wants to emphasize how CTI could have helped prevent or detect this incident. Which statement best describes the role of CTI in this context?

    Select an answer first
  3. 33application · medium

    A security analyst is reviewing a detection rule that flags any API call to `ec2:RunInstances` in a particular AWS account. The rule generates many false positives because the development team frequently creates instances. The analyst wants to use MITRE ATT&CK for Cloud to improve the rule. Which approach is most effective?

    Select an answer first
  4. 34application · medium

    During an incident response, a team identifies that an attacker used a valid but compromised IAM role to create a new user and then used that user to access a database. The team wants to use CTI to prioritize remediation. Which action is most effective?

    Select an answer first
  5. 35expert · hard

    A security architect is designing a detection strategy for a multi-cloud environment (AWS and Azure). The team has limited resources and must prioritize which threats to monitor. They have identified three major risks: misconfigured storage, compromised credentials, and supply chain attacks via third-party libraries. The architect wants to use CTI to decide where to focus. Which approach is most balanced?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCTD” is a trademark of its owner, used for identification only.