
GIAC Cloud Threat Detection
Domain 1Objective 2
Log Centralization GCTD Practice Questions (Page 1)
Part of the Cloud Monitoring Foundations domain, which makes up ~20% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 3–5 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)
46questions here
10free pages
6concepts
Questions 1–5
- 1
A startup uses a centralized logging platform that charges based on data ingested and stored. They want to reduce costs without losing the ability to investigate security incidents. Which strategy is most effective?
Select an answer first - 2
A SOC team needs to search across millions of log entries for a specific user's activity over the past week. The logs are in a central logging platform. What is the most efficient way to perform this search?
Select an answer first - 3
A company uses Google Cloud Platform (GCP) and wants to centralize audit logs into their on-premises SIEM. They need to ensure logs are delivered in near real-time and are not lost if the SIEM is temporarily unavailable. Which ingestion method best meets these requirements?
Select an answer first - 4
Which factor is most important to consider when defining a log retention policy for a centralized logging platform?
Select an answer first - 5
A company has separate logging systems for its web servers, database servers, and cloud infrastructure. The incident response team struggles to piece together the timeline of an attack. What is the primary benefit of centralizing these logs?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCTD” is a trademark of its owner, used for identification only.