
GIAC Enterprise Incident Responder
Domain 2Objective 1
Foundational Cloud Concepts GEIR Practice Questions (Page 5)
Part of the Cloud and Container Forensics domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–35 in this domain), expect 7–12 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)
49questions here
10free pages
8concepts
Questions 21–25
- 21
A company is moving from an IaaS-based application to a SaaS solution. The incident response team is concerned about their ability to collect forensic evidence. What is the most significant change they will face?
Select an answer first - 22
When investigating an incident in a SaaS application, which forensic data is the cloud customer most likely to obtain directly?
Select an answer first - 23
Which virtualization component is responsible for isolating virtual machines from each other and managing their access to physical hardware?
Select an answer first - 24
A forensic analyst is investigating a compromised VM in a virtualized environment. The VM has been suspended by the hypervisor. What is the most forensically sound next step?
Select an answer first - 25
During an incident in an IaaS environment, the IR team suspects that an attacker used a compromised API key to create a new administrative user. Which evidence source would most directly confirm the creation of the user and the API key used?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GEIR” is a trademark of its owner, used for identification only.