Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Cloud Threat Detection

Domain 4Objective 1

Investigating AWS Environments GCTD Practice Questions (Page 10)

Part of the Cloud Provider Investigations domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 5–7 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)

48questions here
10free pages
10concepts

Questions 46–48

  1. 46application · medium

    A GuardDuty finding indicates 'UnauthorizedAccess:IAMUser/InstanceCredentialExfiltration'. The analyst needs to verify if the compromised instance role was used to perform actions outside the instance. Which two data sources should the analyst examine first?

    Select an answer first
  2. 47application · medium

    A security analyst notices that a security group was modified to allow inbound SSH from 0.0.0.0/0. The analyst needs to determine who made the change and when. Which AWS service should the analyst use to find this information?

    Select an answer first
  3. 48expert · hard

    A forensic analyst needs to acquire memory from a running EC2 instance that is suspected of being compromised. The instance is in a production environment and cannot be stopped. Which method should the analyst use to acquire memory with the least impact?

    Select an answer first
Finished these 3 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to GCTD

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCTD” is a trademark of its owner, used for identification only.