
GIAC Enterprise Incident Responder
Domain 2Objective 2
Cloud Response and Analysis GEIR Practice Questions (Page 6)
Part of the Cloud and Container Forensics domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–35 in this domain), expect 7–12 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
9concepts
Questions 26–30
- 26
An incident responder is investigating a compromised AWS EC2 instance that was launched with user data containing a script. The script may have downloaded malware. Which evidence source would reveal the contents of the user data script?
Select an answer first - 27
A company uses AWS Organizations with multiple accounts. An incident is detected in a workload account. The responder needs to determine if the attacker moved laterally to other accounts. Which log source is MOST useful for this analysis?
Select an answer first - 28
Which action is an effective containment strategy for a compromised cloud VM that is communicating with a known command-and-control server?
Select an answer first - 29
Which tool is commonly used to capture full packet data within a cloud virtual network for deep forensic analysis?
Select an answer first - 30
A Docker container on an Azure VM is suspected of running malicious code. The IR team needs to preserve the container's filesystem and runtime state. Which action should they take?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GEIR” is a trademark of its owner, used for identification only.