
GIAC Enterprise Incident Responder
Domain 2Objective 2
Cloud Response and Analysis GEIR Practice Questions (Page 2)
Part of the Cloud and Container Forensics domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–35 in this domain), expect 7–12 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
9concepts
Questions 6–10
- 6
A compromised Azure VM is sending outbound phishing emails. The IR team needs to contain the threat while preserving the ability to analyze the VM's disk. Which containment action should they take?
Select an answer first - 7
Which piece of cloud instance metadata is most likely to be targeted by an attacker to escalate privileges?
Select an answer first - 8
A multinational company uses a SaaS application (e.g., Microsoft 365) and suspects an insider exfiltrated data. The incident responder needs to preserve evidence for potential legal action. The data is stored in a region outside the company's home country. Which consideration is MOST critical when acquiring evidence?
Select an answer first - 9
A company uses AWS with a centralized logging account. During an incident, the IR team needs to determine whether an attacker used the AWS Management Console or the CLI to create a new IAM user. Which log source should they analyze first?
Select an answer first - 10
Which Kubernetes artifact records the actions performed by the kubelet and the container runtime, such as pulling images and starting containers?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GEIR” is a trademark of its owner, used for identification only.