Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Cloud Threat Detection

Domain 1Objective 3

Network and Flow Monitoring GCTD Practice Questions (Page 6)

Part of the Cloud Monitoring Foundations domain, which makes up ~20% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 3–5 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)

40questions here
8free pages
7concepts

Questions 26–30

  1. 26application · medium

    A security analyst is reviewing flow logs from an AWS load balancer and notices a high number of requests from a single IP address to a specific endpoint, with each request lasting only a few milliseconds. The analyst also sees that the load balancer returned HTTP 404 errors for these requests. What is the most likely explanation?

    Select an answer first
  2. 27application · medium

    A security team is integrating VPC flow logs with their SIEM. They want to enrich the flow logs with threat intelligence to identify connections to known malicious IPs. Which approach is most effective?

    Select an answer first
  3. 28application · medium

    A security analyst needs to detect a potential data exfiltration pattern where an internal host is sending large volumes of data to an external IP over HTTPS. The analyst has access to both VPC flow logs and full packet captures from a network tap. The investigation must be completed quickly, and the analyst needs to identify the top talkers and total bytes transferred per connection over the last 24 hours. Which approach is most efficient for this task?

    Select an answer first
  4. 29expert · hard

    A security engineer is troubleshooting why VPC flow logs are not appearing in the SIEM. The flow logs are enabled and delivered to an S3 bucket, but the SIEM collector is not ingesting them. The engineer has verified that the S3 bucket has new files and the SIEM collector has read permissions. What is the next most likely cause to investigate?

    Select an answer first
  5. 30expert · hard

    A security architect is designing a network monitoring solution for a hybrid cloud environment. The environment includes on-premises data centers connected to AWS via a VPN. The architect needs to detect malicious traffic that may be traversing the VPN tunnel. Which data sources should be used?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCTD” is a trademark of its owner, used for identification only.