Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Cloud Threat Detection

Domain 1Objective 2

Log Centralization GCTD Practice Questions (Page 2)

Part of the Cloud Monitoring Foundations domain, which makes up ~20% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 3–5 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)

46questions here
10free pages
6concepts

Questions 6–10

  1. 6expert · hard

    A security team is designing a centralized logging solution. They want to protect logs from unauthorized modification by insiders. They are considering using a separate AWS account for log storage with strict IAM policies. Which additional control is most important to ensure log integrity?

    Select an answer first
  2. 7expert · hard

    A company is designing a log ingestion pipeline for a high-volume cloud environment. They need to ensure that logs are not lost during transmission and that they can be replayed if the SIEM is temporarily unavailable. Which ingestion method is most reliable?

    Select an answer first
  3. 8expert · hard

    A security analyst is investigating a potential data exfiltration. They have logs from the corporate proxy, the cloud access security broker (CASB), and the endpoint detection and response (EDR) tool. The analyst wants to determine if a specific user uploaded a file to a cloud storage service. Which correlation approach is most effective?

    Select an answer first
  4. 9application · medium

    A security analyst is investigating a potential data breach. They have centralized logs from cloud access logs, database audit logs, and application logs. They want to identify which user accessed a specific sensitive record. Which approach is most effective?

    Select an answer first
  5. 10expert · hard

    A SOC team needs to detect a brute-force attack that involves multiple source IPs targeting the same user account. The logs are centralized in a SIEM. Which query or rule would best identify this pattern?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCTD” is a trademark of its owner, used for identification only.