
GIAC Cloud Threat Detection
Domain 4Objective 1
Investigating AWS Environments GCTD Practice Questions (Page 1)
Part of the Cloud Provider Investigations domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 5–7 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)
48questions here
10free pages
10concepts
Questions 1–5
- 1
A Lambda function is suspected of being used to modify IAM policies. The analyst needs to determine if the function has the necessary permissions and if it actually made any changes. Which two data sources should the analyst examine?
Select an answer first - 2
A security operations center uses AWS Security Hub to aggregate findings from GuardDuty, Inspector, and Macie. An analyst notices that a GuardDuty finding is not appearing in Security Hub. What is the most likely cause?
Select an answer first - 3
In a VPC Flow Log record, which field indicates whether the traffic was permitted or blocked by the security groups and network ACLs?
Select an answer first - 4
During an incident, an analyst discovers that an IAM role has a policy allowing 'iam:CreatePolicyVersion' on itself. The analyst suspects privilege escalation. Which combination of steps would best confirm the attack path and determine if it was exploited?
Select an answer first - 5
An investigator needs to determine whether an unauthorized user downloaded a sensitive object from an S3 bucket. Which log source would provide the most direct evidence of the download?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCTD” is a trademark of its owner, used for identification only.