Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Cloud Threat Detection

Domain 1Objective 2

Log Centralization GCTD Practice Questions (Page 5)

Part of the Cloud Monitoring Foundations domain, which makes up ~20% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 3–5 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)

46questions here
10free pages
6concepts

Questions 21–25

  1. 21application · medium

    A security team is centralizing logs from multiple cloud accounts into a single SIEM. They are concerned about an attacker who compromises the SIEM admin account and tries to delete or alter logs to cover their tracks. Which control is most effective at detecting such tampering?

    Select an answer first
  2. 22application · medium

    A startup uses a central SIEM for security monitoring. They want to reduce storage costs while still being able to investigate incidents that occurred up to a year ago. Which retention strategy is most cost-effective?

    Select an answer first
  3. 23application · medium

    A company runs a containerized application on Amazon ECS with Fargate. The security team wants to centralize container stdout logs into their existing self-managed Elasticsearch cluster. They need a solution that requires minimal operational overhead and does not require managing additional servers. Which approach should they choose?

    Select an answer first
  4. 24application · medium

    A DevOps team wants to centralize logs from serverless functions that run for only a few seconds. The functions write logs to the cloud provider's logging service. Which ingestion method is most efficient for getting these logs into the central SIEM?

    Select an answer first
  5. 25application · medium

    A SOC analyst needs to find all failed login attempts across Windows Event Logs, Linux auth logs, and cloud sign-in logs within the last hour. The logs are centralized in a SIEM. Which approach will yield the fastest and most accurate results?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCTD” is a trademark of its owner, used for identification only.