
GIAC Enterprise Incident Responder
Domain 2Objective 2
Cloud Response and Analysis GEIR Practice Questions (Page 3)
Part of the Cloud and Container Forensics domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–35 in this domain), expect 7–12 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
9concepts
Questions 11–15
- 11
A company is investigating a breach in a multi-tenant public cloud environment. The IR team is concerned about legal admissibility of evidence. Which practices should they follow? (Select all that apply.)
Select an answer first - 12
In the shared responsibility model, which party is typically responsible for securing the underlying physical infrastructure in an IaaS deployment?
Select an answer first - 13
An organization is moving to AWS and wants to prepare for cloud incidents. Which preparation activity is most aligned with the preparation phase of the cloud incident response process?
Select an answer first - 14
Which cloud service model gives the customer the least direct access to forensic artifacts such as operating system logs and memory dumps?
Select an answer first - 15
Which method is commonly used to acquire a forensic copy of a cloud VM's disk without powering off the instance?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GEIR” is a trademark of its owner, used for identification only.