
GIAC Cloud Threat Detection
Domain 1Objective 2
Log Centralization GCTD Practice Questions (Page 7)
Part of the Cloud Monitoring Foundations domain, which makes up ~20% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 3–5 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)
46questions here
10free pages
6concepts
Questions 31–35
- 31
A security analyst needs to find all login failures from a specific user in the last 24 hours. Which capability of a centralized logging platform makes this query efficient?
Select an answer first - 32
A security team is designing a centralized logging solution for a healthcare organization that must comply with HIPAA. They need to ensure that only authorized personnel can access logs containing PHI and that access is auditable. Which combination of controls is most appropriate?
Select an answer first - 33
A company must retain security logs for 10 years due to regulatory requirements. They have a limited budget and need to balance cost with the ability to respond to a subpoena that may require producing logs from any point in the retention period. Which storage approach is most appropriate?
Select an answer first - 34
A SIEM platform indexes logs with a field that combines the source IP and destination IP into a single string (e.g., '192.168.1.1-10.0.0.1'). An analyst needs to find all connections from a specific source IP. What is the most efficient query approach?
Select an answer first - 35
What is the primary purpose of log correlation in a centralized logging platform?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCTD” is a trademark of its owner, used for identification only.