Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Cloud Threat Detection

Domain 1Objective 3

Network and Flow Monitoring GCTD Practice Questions (Page 1)

Part of the Cloud Monitoring Foundations domain, which makes up ~20% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 3–5 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)

40questions here
8free pages
7concepts

Questions 1–5

  1. 1expert · hard

    An analyst is investigating a potential data exfiltration from a compromised EC2 instance. The VPC flow logs show a connection from the instance to an external IP on port 443, with a total of 500 MB transferred over 30 minutes. The analyst also has the instance's system logs, which show no unusual processes. Which additional data source would best help determine if the data was actually exfiltrated?

    Select an answer first
  2. 2application · medium

    An analyst is reviewing VPC flow logs and notices a pattern: an internal server is communicating with an external IP on port 22 (SSH) at regular intervals, each connection lasting only a few seconds and transferring minimal data. This pattern has been occurring for several days. Which analysis technique would best help determine if this is malicious?

    Select an answer first
  3. 3application · medium

    A security operations center (SOC) uses a SIEM platform for centralized monitoring. They have enabled VPC flow logs for all VPCs in their cloud environment and want to ensure the flow logs are ingested into the SIEM for correlation with other security events. Which integration approach is most appropriate?

    Select an answer first
  4. 4foundation · easy

    Which cloud resource logs are specifically designed to capture metadata about traffic through a central network hub?

    Select an answer first
  5. 5foundation · easy

    What is a common use of flow log analysis in threat detection?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCTD” is a trademark of its owner, used for identification only.