
GIAC Cloud Threat Detection
Domain 4Objective 2
Investigating Azure Environments GCTD Practice Questions (Page 2)
Part of the Cloud Provider Investigations domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 5–7 from this objective — we provide 55 practice questions to prepare you well beyond it. (estimate)
55questions here
11free pages
14concepts
Questions 6–10
- 6
Which Azure role assignment would be considered a potential privilege escalation if assigned to a user who should only have read-only access?
Select an answer first - 7
Which Azure service provides centralized logging of traffic that is allowed or denied by the organization's network firewall?
Select an answer first - 8
A security analyst is investigating a suspected container escape in an AKS cluster. The analyst needs to identify which pod initiated outbound connections to an external IP and whether any privileged containers were running. Which combination of data sources should be examined?
Select an answer first - 9
An investigator needs to trace a user's authentication attempts, including whether multi-factor authentication (MFA) was used. Which Azure AD log should be examined?
Select an answer first - 10
A user's account in the on-premises Active Directory was compromised, and the attacker used the same credentials to access Azure resources via Azure AD Connect. You need to trace the attacker's actions across both environments. Which log sources should you correlate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCTD” is a trademark of its owner, used for identification only.