Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Cloud Threat Detection

Domain 4Objective 2

Investigating Azure Environments GCTD Practice Questions (Page 1)

Part of the Cloud Provider Investigations domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 5–7 from this objective — we provide 55 practice questions to prepare you well beyond it. (estimate)

55questions here
11free pages
14concepts

Questions 1–5

  1. 1application · medium

    A database administrator notices unusual queries running against an Azure SQL database. The security team needs to determine whether these queries were part of an attack and whether any data was exported. Which log source should be analyzed to see the actual query text and the client IP?

    Select an answer first
  2. 2foundation · easy

    During an Azure incident investigation, an analyst needs to establish a complete inventory of all cloud resources that exist across the organization's subscriptions. Which Azure service provides a centralized, queryable view of all resources across subscriptions, resource groups, and regions?

    Select an answer first
  3. 3application · medium

    During an incident, an analyst must quickly identify all resources that were created or modified in the last 24 hours across multiple subscriptions. The analyst needs a single view that lists resources and their change history. Which approach provides the most efficient baseline?

    Select an answer first
  4. 4application · medium

    A security team is reviewing an incident where a user with Contributor role on a subscription created a new role assignment granting themselves Owner. The team needs to identify when the role assignment was created and by whom. Which log source should be examined?

    Select an answer first
  5. 5expert · hard

    A security incident involves the theft of secrets from Azure Key Vault. You need to determine whether the secrets were accessed by an authorized application or by an attacker who compromised the application's credentials. You have access to Key Vault audit logs and Azure AD sign-in logs. What is the best way to distinguish between the two?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCTD” is a trademark of its owner, used for identification only.