
GIAC Enterprise Incident Responder
Domain 2Objective 2
Cloud Response and Analysis GEIR Practice Questions (Page 4)
Part of the Cloud and Container Forensics domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–35 in this domain), expect 7–12 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
9concepts
Questions 16–20
- 16
A GCP Compute Engine instance was compromised. The incident responder needs to determine which IAM roles the instance's service account had at the time of the incident. Which source provides the most accurate historical view of the service account's permissions?
Select an answer first - 17
A Kubernetes cluster in EKS experienced a security incident. The IR team needs to determine which user or service account executed a `kubectl exec` command into a pod. Which log source should they analyze?
Select an answer first - 18
An Azure VM is suspected of running cryptocurrency miners. The IR team wants to preserve forensic evidence without altering the VM's state. Which action should they take first?
Select an answer first - 19
Which phase of the cloud incident response process involves actions such as taking snapshots, preserving logs, and isolating the affected instance to prevent further damage?
Select an answer first - 20
A Kubernetes cluster in AKS is suspected of running a malicious container. The responder needs to preserve evidence of the container's filesystem and runtime behavior without stopping the pod. Which action is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GEIR” is a trademark of its owner, used for identification only.