
GIAC Enterprise Incident Responder
Domain 2Objective 1
Foundational Cloud Concepts GEIR Practice Questions (Page 3)
Part of the Cloud and Container Forensics domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–35 in this domain), expect 7–12 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)
49questions here
10free pages
8concepts
Questions 11–15
- 11
In the data lifecycle, which stage involves creating a forensic copy of evidence to prevent alteration of the original data?
Select an answer first - 12
A company uses a hybrid cloud environment. An incident responder needs to correlate an attack that started on-premises and moved to the cloud. Which logging strategy is most effective?
Select an answer first - 13
A company uses a SaaS email platform and suspects a user's mailbox was compromised. The incident responder needs to obtain forensic evidence of the attacker's actions. Which action is most appropriate given the shared responsibility model?
Select an answer first - 14
A company uses an IaaS cloud provider. An incident responder needs to collect evidence from a compromised virtual machine. Which evidence source is the customer responsible for collecting?
Select an answer first - 15
An organization's incident response team needs to acquire forensic images of virtual machines in a private cloud environment. What is the most important consideration when planning the acquisition?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GEIR” is a trademark of its owner, used for identification only.