
GIAC Cloud Threat Detection
Domain 2Objective 1
Host OS Monitoring GCTD Practice Questions (Page 9)
Part of the Cloud Infrastructure Monitoring domain, which makes up ~37% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~19–30 in this domain), expect 5–8 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)
51questions here
11free pages
8concepts
Questions 41–45
- 41
A cloud security team wants to detect host-based intrusions on Windows VMs. They need a solution that can analyze system calls and process activity in real time, and integrate with their existing SIEM. Which approach best meets these requirements?
Select an answer first - 42
A security analyst wants to detect a memory leak in an application running on a cloud VM. Which host-level metric should be monitored over time?
Select an answer first - 43
Which of the following is a typical data source that a host-based intrusion detection system (HIDS) uses to detect suspicious activity?
Select an answer first - 44
A security analyst is investigating a suspicious process on a Linux VM. The process name is 'httpd' but it is running from /tmp and has a high CPU usage. The analyst wants to confirm whether this is the legitimate Apache web server. Which check would be most definitive?
Select an answer first - 45
A security team is investigating a potential rootkit on a Linux VM. The process list shows a process named 'kworker' that is using high CPU. The team suspects the process is hidden or spoofed. Which technique would best confirm whether the process is legitimate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCTD” is a trademark of its owner, used for identification only.