GIAC GCFR Certification Sample Questions

GCFR Dumps, GCFR PDF, GCFR VCE, GIAC Cloud Forensics Responder VCE, GIAC GCFR PDFThe purpose of this Sample Question Set is to provide you with information about the GIAC Cloud Forensics Responder (GCFR) exam. These sample questions will make you very familiar with both the type and the difficulty level of the questions on the GCFR certification test. To get familiar with real exam environment, we suggest you try our Sample GIAC GCFR Certification Practice Exam. This sample practice exam gives you the feeling of reality and is a clue to the questions asked in the actual GIAC Cloud Forensics Responder (GCFR) certification exam.

These sample questions are simple and basic questions that represent likeness to the real GIAC Cloud Forensics Responder exam questions. To assess your readiness and performance with real-time scenario based questions, we suggest you prepare with our Premium GIAC GCFR Certification Practice Exam. When you solve real time scenario based questions practically, you come across many difficulties that give you an opportunity to improve.

GIAC GCFR Sample Questions:

01. CloudTrail records in an AWS account show a series of destructive API calls made by a principal whose session name is ir-automation-07. The responder needs to establish who set that session in motion.
Which record answers that?
a) The trust policy of the role, which lists every principal that has assumed it and the times at which each did so
b) The AssumeRole event that issued the session
c) The instance metadata of the resource named in the session, which records the identity that launched it
d) The IAM credential report for the account, which lists each principal and when it was last active
 
02. A Kubernetes cluster runs a development workload and a payment workload in separate namespaces on a shared pool of worker nodes. A container in the development namespace is escaped to its node.
What does that give the attacker?
a) Access to the payment namespace's Secret objects wherever they are stored in the cluster
b) Access to the pods in the development namespace only, which is the boundary the node enforces
c) Access to the API server as a cluster administrator, granted by the node's own identity
d) Access to every pod scheduled on that node, whichever namespace they belong to
 
03. While scoping a Kubernetes intrusion, a responder finds that the attacker's service account was granted its permissions through a ClusterRoleBinding rather than a RoleBinding.
What does that distinction tell the responder about the blast radius?
a) The permissions apply across every namespace in the cluster rather than within a single one
b) The permissions were granted at the node level and take effect only on the nodes the service account's pods were scheduled onto
c) The permissions apply to the cluster's control-plane components only, and not to any workload namespace the attacker could reach
d) The permissions match in scope and differ only in object placement
 
04. The API server of a Google Kubernetes Engine cluster was reachable from the internet and was refusing requests that carried no credentials. The cluster's audit configuration was left as Google Cloud installed it.
What should the responder expect of those unauthenticated requests?
a) They appear in the control-plane audit log only once the cluster is configured to record anonymous access separately
b) They are turned away at the network edge before the API server sees them, leaving no trace of the attempt
c) They are recorded in the kubelet's log on whichever node served the request
d) They appear in the control-plane audit log as denied requests, with the requester recorded as an unauthenticated identity
 
05. An attacker ran a tool inside a Kubernetes pod, and the tool wrote its output to a file on the container's own filesystem rather than to standard output. The pod has since been deleted and replaced by its deployment controller.
What has happened to that output?
a) It was collected as part of the pod's container log and remains available under the deleted pod's name in the central log store
b) It was written into the node's kubelet log, where it survives the pod's removal
c) It was never collected by the cluster's log pipeline, and it went with the container's filesystem when the pod was removed
d) It was preserved in the deployment's revision history alongside the pod template
 
06. While reviewing a Google Cloud project's audit history, a responder finds an entry describing a Compute Engine instance being restarted. No principal on the entry corresponds to any identity the organization administers, and the entry is not an Admin Activity record.
What does the entry most likely indicate?
a) The restart was requested through a service account whose identity was omitted from the entry
b) An external actor reached the Compute Engine API without credentials and issued the restart
c) The restart was requested by a user account that was deleted afterwards, so the entry's principal matches nothing in the directory
d) Google Cloud itself acted on the instance, and the entry is a System Event record of a platform-initiated action rather than one a principal requested
 
07. A responder establishes that an attacker obtained the contents of every Secret object in a Kubernetes cluster. The control-plane audit log contains no request that reads those objects over the period concerned, and the audit policy in force is confirmed to record read requests against Secret objects.
What best explains the absence of those requests?
a) The Secrets were read through the kubelet on each node, which serves object content without contacting the API server
b) The cluster stores Secret values outside etcd, in the node's local configuration
c) The attacker read the cluster's state directly from etcd, which does not pass through the API server
d) The audit policy in force excludes read requests against Secret objects, while continuing to record every write against them
 
08. VPC flow log records for an Amazon EC2 instance show an outbound connection to an external service accepted, and the corresponding return traffic rejected.
Which control produced that combination?
a) The operating system firewall on the instance, whose decisions appear in the flow log
b) The subnet route table, which lacked a return path to the external service
c) The instance security group, whose outbound rules permitted the request while its inbound rules had no entry matching the reply
d) A network access control list on the subnet, which evaluates each direction separately
 
09. A Google Cloud project's VPC Flow Logs show a Compute Engine instance sending a large volume of data to an external address over several hours. The instance had read access to a Cloud Storage bucket, and Data Access audit logging for Cloud Storage is enabled in the project. The investigation needs to establish which objects in that bucket were read during the same window.
What is the correct next step?
a) Query the Data Access audit entries for the bucket, which name the objects and the operations against them
b) Retrieve the instance's serial console output for the period the flow records cover and look for the object names
c) Correlate the byte counts in the flow records against the recorded sizes of every object the bucket holds, and match them
d) Reconstruct the transferred content from the payload captured in the flow records
 
10. In a compromised Microsoft 365 mailbox an investigator finds an inbox rule that moves any message containing the words 'password', 'suspicious' or 'verify' straight to the deleted items folder.
What is the forensic significance of that rule?
a) It indicates that the mailbox has exceeded its storage allocation and is shedding low-priority mail
b) It conceals security notifications and replies from the account owner
c) It prevents the matching messages from being recorded in the Unified Audit Log
d) It exfiltrates the messages it matches by copying them to an address the actor controls before deleting them

Answers:

Question: 01
Answer: b
Question: 02
Answer: d
Question: 03
Answer: a
Question: 04
Answer: d
Question: 05
Answer: c
Question: 06
Answer: d
Question: 07
Answer: c
Question: 08
Answer: d
Question: 09
Answer: a
Question: 10
Answer: b

Note: For any error in GIAC Cloud Forensics Responder (GCFR) certification exam sample questions, please update us by writing an email on feedback@edusum.com.

Rating: 4.9 / 5 (79 votes)