
GIAC Cloud Threat Detection
Domain 2Objective 1
Host OS Monitoring GCTD Practice Questions (Page 1)
Part of the Cloud Infrastructure Monitoring domain, which makes up ~37% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~19–30 in this domain), expect 5–8 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)
51questions here
11free pages
8concepts
Questions 1–5
- 1
What is a common way to integrate host OS monitoring with cloud-native monitoring services?
Select an answer first - 2
What is the purpose of configuring alerts for host OS security incidents?
Select an answer first - 3
A company's FIM solution monitors critical system files, but it generates a high volume of alerts during legitimate software updates. The security team wants to reduce alert noise without losing visibility into unauthorized changes. Which approach is most effective?
Select an answer first - 4
A company uses AWS CloudWatch for monitoring its EC2 instances. They want to centralize host OS logs (e.g., /var/log/auth.log) and create alerts for suspicious activities. Which solution best integrates with CloudWatch?
Select an answer first - 5
What is the primary function of a host-based intrusion detection system (HIDS)?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCTD” is a trademark of its owner, used for identification only.