
GIAC Enterprise Incident Responder
Domain 2Objective 2
Cloud Response and Analysis GEIR Practice Questions (Page 7)
Part of the Cloud and Container Forensics domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–35 in this domain), expect 7–12 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
9concepts
Questions 31–35
- 31
An Azure VM is suspected of communicating with a malicious IP. The IR team needs to confirm the communication and determine if any data was exfiltrated. They have enabled NSG flow logs, but the logs do not show the payload. What should they do next?
Select an answer first - 32
Which challenge in cloud forensics is directly related to the fact that multiple customers may share the same physical hardware?
Select an answer first - 33
An incident responder needs to acquire forensic evidence from a compromised AWS EC2 instance. The instance is still running. Which acquisition method preserves the most volatile data first?
Select an answer first - 34
Which practice is essential to maintain the chain of custody for cloud forensic evidence?
Select an answer first - 35
A company uses a hybrid cloud with on-premises servers and AWS. An incident is detected in the cloud environment. The incident response plan was written for on-premises incidents. The responder must adapt the plan. Which adjustment is MOST important?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GEIR” is a trademark of its owner, used for identification only.