Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Cloud Threat Detection

Domain 1Objective 3

Network and Flow Monitoring GCTD Practice Questions (Page 7)

Part of the Cloud Monitoring Foundations domain, which makes up ~20% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 3–5 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)

40questions here
8free pages
7concepts

Questions 31–35

  1. 31expert · hard

    A company has enabled VPC Flow Logs and is delivering them to CloudWatch Logs. The security team is not seeing any flow logs for a specific network interface, even though other interfaces in the same VPC are logging correctly. The flow log status is 'ACTIVE'. What is the most likely cause?

    Select an answer first
  2. 32application · medium

    A cloud administrator enabled VPC flow logs for a new VPC, but after 24 hours, no flow log files have been delivered to the designated S3 bucket. The flow log configuration shows as 'Active'. What is the most likely cause of this issue?

    Select an answer first
  3. 33application · medium

    A security operations center (SOC) uses a SIEM platform for centralized monitoring. They have enabled VPC Flow Logs in AWS and want to ensure the flow log data is available in the SIEM for correlation with other security events. What is the most efficient way to achieve this?

    Select an answer first
  4. 34application · medium

    A cloud security team is designing a monitoring strategy for a multi-account AWS environment. They need to detect lateral movement between EC2 instances in different VPCs that are connected via a transit gateway. Which data sources should they prioritize for this detection?

    Select an answer first
  5. 35application · medium

    A security analyst is investigating a potential data exfiltration from an application running on EC2 instances behind an Application Load Balancer (ALB). The analyst needs to determine if the exfiltration occurred through the load balancer or directly from the instances. Which combination of log sources would provide the most complete picture?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCTD” is a trademark of its owner, used for identification only.