
GIAC Enterprise Incident Responder
Domain 2Objective 1
Foundational Cloud Concepts GEIR Practice Questions (Page 2)
Part of the Cloud and Container Forensics domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–35 in this domain), expect 7–12 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)
49questions here
10free pages
8concepts
Questions 6–10
- 6
A company uses a PaaS service to host a web application. During an incident, the IR team needs to collect logs from the application and the platform. According to the shared responsibility model, which logs is the customer most likely able to access directly?
Select an answer first - 7
During an incident, a responder needs to determine which user deleted a critical cloud resource. What is the most reliable evidence source?
Select an answer first - 8
An incident responder needs to identify all API calls made by a compromised service account in a cloud environment. Which log source should be examined?
Select an answer first - 9
A company uses a serverless computing platform (FaaS) for a critical application. During an incident, the responder needs to collect evidence of unauthorized function invocations. What is the most appropriate evidence source?
Select an answer first - 10
An organization is moving a legacy application to the cloud. The application requires custom network configurations and the IR team needs full access to the operating system for forensic purposes. The organization also wants to minimize the management overhead of the underlying infrastructure. Which cloud service model best balances these requirements?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GEIR” is a trademark of its owner, used for identification only.