Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Cloud Threat Detection

Domain 4Objective 1

Investigating AWS Environments GCTD Practice Questions (Page 4)

Part of the Cloud Provider Investigations domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 5–7 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)

48questions here
10free pages
10concepts

Questions 16–20

  1. 16application · medium

    A security team is investigating a Lambda function that is suspected of exfiltrating data. The function's CloudWatch Logs show calls to an external IP address, but the function's IAM role does not have permission to access any S3 buckets. Which additional investigation step would best confirm whether the function is exfiltrating data?

    Select an answer first
  2. 17application · medium

    A security analyst is investigating a potential data exfiltration from an S3 bucket. S3 access logs show repeated `GET` requests for a specific object from a range of IP addresses, but the requests are spread over several hours. Which additional analysis would best determine whether this is a coordinated exfiltration attempt?

    Select an answer first
  3. 18foundation · easy

    An investigator needs to review the network traffic between EC2 instances in a VPC to identify potential command-and-control communication. Which AWS service provides detailed information about IP traffic flows within a VPC?

    Select an answer first
  4. 19application · medium

    A security analyst is reviewing AWS CloudTrail logs after a suspected compromise. The analyst notices a series of `AssumeRole` API calls from an IAM user to a role that has `iam:CreateUser` and `iam:AttachUserPolicy` permissions. The calls originate from an unfamiliar IP address. Which additional data source would best help determine whether the role was used to create a new IAM user for persistence?

    Select an answer first
  5. 20foundation · easy

    An investigator wants to see the history of configuration changes to an EC2 security group to determine when an unauthorized inbound rule was added. Which AWS service provides this configuration history?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCTD” is a trademark of its owner, used for identification only.