Skip to main content

GCFR Online Exam

GIAC Cloud Forensics Responder (GCFR)

82 questions available ยท Page 1 of 9

View study plans
Question 1 Single choice

What unique identifier is used by AWS to identify a specific account and allow integration with external organizations?

  1. A

    Public Key

  2. B

    Token

  3. C

    ARN

  4. D

    SID

Show answer and explanation

Correct answer: C

Question 2 Single choice

What method does Google use to alert Gmail account holders that they may be under attack by government sponsored attackers?

  1. A

    Message upon successful logon

  2. B

    SMS text message

  3. C

    Email sent to the user

  4. D

    Alert sent to recovery account

Show answer and explanation

Correct answer: A

Question 3 Single choice

Which of the following Windows agents would need to be configured on an Azure VM for an investigator to query Its operating system logs sent to Azure Storage?

  1. A

    Azure Monitor

  2. B

    Diagnostic Extension

  3. C

    Dependency

  4. D

    Log Analytics

Show answer and explanation

Correct answer: B

Question 4 Single choice

At what point of the OAuth delegation process does the Resource Owner approve the scope of access to be allowed?

  1. A

    After user credentials are accepted by the Authorization Server

  2. B

    Once the OAuth token is accepted by the Application

  3. C

    When the Resource Server receives the OAuth token

  4. D

    Before user credentials are sent to the Authentication Server

Show answer and explanation

Correct answer: A

Question 5 Single choice

A company using PaaS to host and develop their software application is experiencing a DOS attack.

What challenge will a DFIR analyst experience when investigating this attack?

  1. A

    Restricted access to their application logs

  2. B

    Resource scaling will affect access to logs

  3. C

    Network logs are unavailable for review

  4. D

    Network monitoring disabled by the company

Show answer and explanation

Correct answer: C

Question 6 Single choice

An attacker successfully downloaded sensitive data from a misconfigured GCP bucket. Appropriate logging was not enabled.

Where can an analyst find the rough time and quantity of the data downloaded?

  1. A

    Billing Section

  2. B

    C;loud Trace

  3. C

    Cloud Logging

  4. D

    Security Command Center

Show answer and explanation

Correct answer: A

Question 7 Single choice

In Azure, which of the following describes a "Contributor"?

  1. A

    A collection of permissions such as read, write, and delete

  2. B

    A designation on a PKI certificate

  3. C

    A specification of who can access a resource group

  4. D

    An object representing an entity

Show answer and explanation

Correct answer: A

Question 8 Single choice

Which is the effective access when aws user is assigned to an S3 bucket?

  1. A

    A user must have an employee account

  2. B

    A user must have an account under any AWS account

  3. C

    A user must be under the same AWS account as the S3 bucket

  4. D

    A user must have the AWS IAM role assigned

Show answer and explanation

Correct answer: C

Question 9 Single choice

What can be inferred about the ARN below?

arn:aws:!am::457787814323:user/giac

  1. A

    giac's is a user In the AWS account 457787814323

  2. B

    giac's access Is testf kted to resources owned by AWS tenant 457787814323

  3. C

    giac's Is limited to roles defined under a single AWS organization

  4. D

    giac's user's access key 10 is 457787814323

Show answer and explanation

Correct answer: A

Question 10 Single choice

The Azure PowerShell output below is an example of which of the following?

  1. A

    Role assignment

  2. B

    Managed identity

  3. C

    Role definition

  4. D

    Service principal

Show answer and explanation

Correct answer: B