
GIAC Cloud Threat Detection
Domain 1Objective 3
Network and Flow Monitoring GCTD Practice Questions (Page 5)
Part of the Cloud Monitoring Foundations domain, which makes up ~20% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 3–5 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)
40questions here
8free pages
7concepts
Questions 21–25
- 21
A company runs a web application behind an Application Load Balancer (ALB) in AWS. The security team wants to detect attempts to exploit a specific web application vulnerability by analyzing HTTP request patterns. Which data source should they use?
Select an answer first - 22
What is the primary purpose of network monitoring in a cloud environment?
Select an answer first - 23
A security analyst is investigating a potential data breach in a cloud environment. The analyst needs to determine which internal resources communicated with a known malicious external IP address over the past 30 days. Which data source would be most effective for this investigation?
Select an answer first - 24
A SOC team is integrating VPC flow logs with their SIEM. They want to detect beaconing activity, which is characterized by regular, periodic connections to an external IP. They have enabled flow logs with a 10-minute aggregation interval. Which of the following is the most significant limitation of this configuration for detecting beaconing?
Select an answer first - 25
Which of the following is a primary source of network flow data in a cloud platform?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCTD” is a trademark of its owner, used for identification only.