
GIAC Cloud Threat Detection
Domain 4Objective 2
Investigating Azure Environments GCTD Practice Questions (Page 9)
Part of the Cloud Provider Investigations domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 5–7 from this objective — we provide 55 practice questions to prepare you well beyond it. (estimate)
55questions here
11free pages
14concepts
Questions 41–45
- 41
During an incident response, you discover that a new user was created with 'Contributor' rights on a subscription. The user was not created through the normal HR process. You suspect an ARM template deployment. What should you review to confirm this?
Select an answer first - 42
Which Microsoft service provides a cloud-native SIEM and SOAR solution that can ingest Azure Activity Logs, Azure AD logs, and other data sources for threat hunting and alert correlation?
Select an answer first - 43
Which of the following is a potential indicator of a malicious ARM template deployment?
Select an answer first - 44
What does the 'Compliance state' of a resource in Azure Policy indicate?
Select an answer first - 45
Which Microsoft Defender for Cloud feature provides continuous assessment of Azure resources against security best practices and compliance standards?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCTD” is a trademark of its owner, used for identification only.