
GIAC Cloud Threat Detection
Domain 1Objective 2
Log Centralization GCTD Practice Questions (Page 6)
Part of the Cloud Monitoring Foundations domain, which makes up ~20% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 3–5 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)
46questions here
10free pages
6concepts
Questions 26–30
- 26
Which security measure is essential to prevent unauthorized users from reading sensitive log data in a centralized logging platform?
Select an answer first - 27
A security team wants to detect attacks that span multiple cloud services, such as an attacker who compromises a web application and then uses its service principal to access storage. What is the primary benefit of aggregating logs from all cloud services into a central repository?
Select an answer first - 28
A multinational company operates in regions with strict data residency laws. They want to centralize logs for global threat detection but must ensure that logs from certain regions do not leave the country. Which architecture best satisfies both centralization and data residency?
Select an answer first - 29
A security team is designing a centralized logging pipeline. They need to ensure that logs are not lost if the central SIEM is down, and they also need to prevent unauthorized access to the log data in transit. Which architecture best meets both requirements?
Select an answer first - 30
A security team must retain logs for at least one year to meet a compliance requirement, but they also want to control storage costs. Which approach best balances these needs?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCTD” is a trademark of its owner, used for identification only.