
GIAC Cloud Threat Detection
Domain 4Objective 2
Investigating Azure Environments GCTD Practice Questions (Page 11)
Part of the Cloud Provider Investigations domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 5–7 from this objective — we provide 55 practice questions to prepare you well beyond it. (estimate)
55questions here
11free pages
14concepts
Questions 51–55
- 51
During an incident, an analyst needs to identify which Azure VM communicated with a known malicious IP address over the past week. The VMs are in a single subnet protected by a network security group (NSG). Which log source should be enabled and queried to map the traffic?
Select an answer first - 52
An investigator needs to examine the logs of a specific pod in an AKS cluster to identify suspicious activity. Which command retrieves the logs for a pod?
Select an answer first - 53
Which Azure feature allows an investigator to create a new VM from a snapshot of a disk for offline analysis?
Select an answer first - 54
Your organization uses Microsoft Sentinel. You need to detect a potential brute-force attack against a VM's RDP endpoint. Which data sources should you enable and correlate in Sentinel?
Select an answer first - 55
You are investigating a potential data exfiltration and need to identify all storage accounts in the organization that were created in the last 30 days. You have access to multiple subscriptions. Which tool should you use to quickly enumerate these resources?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GCTD
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCTD” is a trademark of its owner, used for identification only.