Halloween Special 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: clap70

GCFR GIAC Cloud Forensics Responder (GCFR) Questions and Answers

Questions 4

An organization has optimized their S3 buckets to quickan their data collection across a global infrastructure. Which reflects the bucket URL root?

Options:

A.

bucketname.s3-accelerate.amazonaws.com

B.

bucketname.s3.us-west-2.mazonaws.com

C.

s3.us-west-2,amazonaws.com/bucketname

D.

bucketname buttcetname.amazonaws.com

Buy Now
Questions 5

What is a best practice recommendation when using API keys for AWS access?

Options:

A.

Delete the account's default access keys

B.

Define specific role permissions

C.

Enable MFA protection

D.

Configure STS one-time tokens

Buy Now
Questions 6

What type of AWS log is the following snippet an example of?

Options:

A.

Web Application firewall Log

B.

VPC Flow Log

C.

Load Balancer Log

D.

Route 53 Query Log

Buy Now
Questions 7

What is shown in the screenshot?

Options:

A.

Google threat types

B.

Windows event channels

C.

Mitre ATT&CK tactics

D.

CIS critical controls

Buy Now
Questions 8

Which of the following is available with the free tier of service for CloudTrail?

Options:

A.

Single trail of management events delivered to Amazon

B.

Access to data-related API Cloud Trail events

C.

Access to CloudTrail Insights to detect anomalies

D.

Default trail maintained by AWS for more than 90 days

Buy Now
Questions 9

A system administration team has deployed several laaS platform servers and intend to host a custom application in the cloud. Which of the following is the responsibility of the system administration team with this architecture?

Options:

A.

Transferring the private key* for encrypting application data to the cloud provider

B.

Creating a redundant data center to provide global backups

C.

Fixing software vulnerabilities in the code on the perimeter firewall

D.

System security patches and updates for the application servers

Buy Now
Questions 10

An engineer has set up log forwarding for a new data source and wants to use that data to run reports and create dashboards in Kibana. What needs to be created in order to properly handle these logs?

Options:

A.

Row

B.

Parser

C.

ingest script

D.

Beat

Buy Now
Questions 11

An investigator is evaluating a client's Microsoft 365 deployment using the web portals and has identified that the Purview compliance portal states that the Unified Audit Logs are not enabled. Based on the additional Information gathered below, what is most likely the cause of this configuration message?

Subscription creation date: December 4, 2021 Number of administrators: 2 Number of non-administrative user accounts: 74 Last tenant administration change: December 4,2021

Options:

A.

Explicitly been disabled by an administrator

B.

License was downgraded lower than an E5 license

C.

Tenant is configured to forward logs externally

D.

Default configuration, service was never enabled

Buy Now
Questions 12

Which AWS policy type specifies the maximum resource permissions for in organization or organizational unit (OU)?

Options:

A.

Resource

B.

Permission Boundaries

C.

Session

D.

Service Control

Buy Now
Questions 13

In which scenario would an investigator collect NetFlow logs rather than PCAP logs?

Options:

A.

To save on storage space

B.

For detailed network monitoring

C.

For deep packet inspection

D.

To collect application layer data

Buy Now
Questions 14

An attacker successfully downloaded sensitive data from a misconfigured GCP bucket. Appropriate logging was not enabled. Where can an analyst find the rough time and quantity of the data downloaded?

Options:

A.

Billing Section

B.

C;loud Trace

C.

Cloud Logging

D.

Security Command Center

Buy Now
Questions 15

Which AWS Storage option is ideal for storing incident response related artifacts and logs?

Options:

A.

Elastic File Store

B.

ElastiCache

C.

Elastic Block Storage

D.

Simple Storage Service

Buy Now
Questions 16

An engineer is troubleshooting a complaint that a web server in AWS cannot receive incoming traffic, but the server can connect to the internet otherwise. What is needed to solve this problem?

Options:

A.

VPC Subnet

B.

NAT Gateway

C.

Network Security Group

D.

Internet Gateway

Buy Now
Questions 17

Use Kibana to analyze the Azure AD sign-in logs in the azure-* index. On March 31st, 2021, what is the timestamp of the earliest failed login attempt for the accountdcr0ss5pymtechlabs.com?

ViewVM

Options:

A.

19:21:34

B.

18:11:07

C.

19:01:27

D.

01:04:24

E.

18:12:04

F.

19:02:06

G.

01:02:56

Buy Now
Questions 18

Which performance feature of an Amazon EC2 instance is configured to add additional resources based on set trigger points?

Options:

A.

Burstable

B.

Optimized

C.

Managed

D.

Accelerated

Buy Now
Questions 19

What Amazon EC2 instance prefix should be monitored to detect potential crypto mining?

Options:

A.

C

B.

P

C.

R

D.

I

Buy Now
Questions 20

Below is an extract from a Server Access Log showing arecord for a request made to an AWS S3 bucket. What does the first field starting with "385f9e" represent?

Options:

A.

Bucket Owner

B.

Request ID

C.

Host ID

D.

Cipher Suite

Buy Now
Questions 21

What is the recommended storage type when creating an initial snapshot of a VM in Azure for forensic analysis?

Options:

A.

Standard SSD

B.

Ultra Disk

C.

Premium SSD

D.

Standard HDD

Buy Now
Questions 22

Which is a limitation when adding GPUs to Google cloud VMs?

Options:

A.

They can only be added at VM creation

B.

Preemptible VMs do not support GPU addition

C.

Google limits the GPUs assigned to a single VM

D.

They are only available in specific zones

Buy Now
Questions 23

What is the example AWS data below an example of?

Options:

A.

EC2 Configuration

B.

S3 Configuration

C.

Network Security Group

D.

IAM Policy

Buy Now
Questions 24

The Azure URI for the Develop VM is shown below. What will change in the notation when referencing the VM's OS disk?

Options:

A.

Resource Type

B.

Provider

C.

Resource Group

D.

Subscription ID

Buy Now
Exam Code: GCFR
Exam Name: GIAC Cloud Forensics Responder (GCFR)
Last Update: Oct 21, 2024
Questions: 82
GCFR pdf

GCFR PDF

$24  $80
GCFR Engine

GCFR Testing Engine

$28.5  $95
GCFR PDF + Engine

GCFR PDF + Testing Engine

$39  $130