GIAC Cloud Forensics Responder (GCFR) - GCFR Exam Practice Test
What is a best practice recommendation when using API keys for AWS access?
Correct Answer: B
Vote an answer
Sensitive company data is found leaked on the internet, and the security team didn't get any alert and is unsure of how the breach occurred.
Which logs would be a preferable starting point for an investigation?
Which logs would be a preferable starting point for an investigation?
Correct Answer: D
Vote an answer
Which of the following actions described below would populate the suggestions table on an Android phone?
Correct Answer: C
Vote an answer
What logical AWS structure type is used to chain together accounts in a trust relationship which allows for single sign-on and cross-account management?
Correct Answer: A
Vote an answer
A data exfiltration investigation of a GCP storage bucket is limited to the information logged by default in the Cost Table of Google's Cloud Billing. What information will investigators be able to gather?
Correct Answer: D
Vote an answer
A threat actor conducts brute force attacks against SSH services to gain Initial access. This attack technique falls under which category of the Google Workspace MITRE ATT&CK matrix?
Correct Answer: B
Vote an answer
A company using PaaS to host and develop their software application is experiencing a DOS attack. What challenge will a DFIR analyst experience when investigating this attack?
Correct Answer: A
Vote an answer
Which statement describes how an organization could use IPv6 in a Google Cloud deployment?
Correct Answer: C
Vote an answer
An analyst successfully authenticated to Microsoft 365 using the following command. What would cause the analyst to be unable to search UAL events for a specific time period?
Ps> connect fxrhangeOnline userPrincipalName sysanalystatexanpteco.com
Ps> connect fxrhangeOnline userPrincipalName sysanalystatexanpteco.com
Correct Answer: D
Vote an answer