
GIAC Cloud Threat Detection
Domain 1Objective 3
Network and Flow Monitoring GCTD Practice Questions (Page 2)
Part of the Cloud Monitoring Foundations domain, which makes up ~20% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 3–5 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)
40questions here
8free pages
7concepts
Questions 6–10
- 6
A security architect is designing a monitoring solution for a multi-account cloud environment. They need to capture network flow data across all VPCs and on-premises connections via a transit gateway. Which approach provides the most comprehensive flow data?
Select an answer first - 7
Which of the following is a common issue when analyzing flow log data?
Select an answer first - 8
Which type of data is typically collected by network monitoring in a cloud environment?
Select an answer first - 9
When configuring flow log collection for a cloud network resource, what does the capture interval determine?
Select an answer first - 10
A security operations center (SOC) is integrating VPC Flow Logs into their SIEM. They have a requirement to detect anomalies in real-time and also to support historical investigations. The SIEM has limited processing capacity, and the team wants to minimize the volume of data sent to the SIEM while still capturing all relevant traffic. What approach should they take?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCTD” is a trademark of its owner, used for identification only.