
GIAC Enterprise Incident Responder
Domain 2Objective 2
Cloud Response and Analysis GEIR Practice Questions (Page 9)
Part of the Cloud and Container Forensics domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–35 in this domain), expect 7–12 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
9concepts
Questions 41–45
- 41
A company uses a SaaS CRM. An incident is suspected, and the responder needs to acquire evidence. Which evidence source is MOST likely accessible to the customer under the shared responsibility model?
Select an answer first - 42
Which Azure service provides a centralized log of management events, including who created, modified, or deleted a resource in the Azure subscription?
Select an answer first - 43
What is the primary purpose of the instance metadata service in cloud environments?
Select an answer first - 44
A company uses a SaaS application (e.g., Microsoft 365) and suspects an account takeover. The IR team needs to obtain forensic evidence. Which evidence source is most likely available to the customer under the shared responsibility model?
Select an answer first - 45
Which remediation action is most appropriate after confirming that a cloud account's access keys were compromised?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GEIR” is a trademark of its owner, used for identification only.