Latest GIAC GCFR Practice Test Questions, GIAC Cloud Forensics Responder (GCFR) Exam Dumps [Q38-Q55]

Share

Latest GIAC GCFR Practice Test Questions, GIAC Cloud Forensics Responder (GCFR) Exam Dumps

Aug-2024 Pass GIAC GCFR Exam in First Attempt Easily

NEW QUESTION # 38
Which Azure blob storage option is typically used to store virtual hard drive (VHD) Ales?

  • A. File
  • B. page
  • C. Block
  • D. Append

Answer: B


NEW QUESTION # 39
What AWS service will allow an organization to set custom compliance metrics and force compliance on an organizational, sub-organizational, or individual account level?

  • A. Security Hub
  • B. Inspector
  • C. Cognllo
  • D. Config

Answer: D


NEW QUESTION # 40
An investigator confirms that phishing emails sent to users in an organization ate not being sent to their Gmall Spam folder. What is a possible cause for this?

  • A. Compliance based rules need to be configured to detect phishing emails
  • B. The default setting for enhanced pre-delivery message scanning was changed
  • C. A third party application needs to be installed to detect phishing emails
  • D. The security sandbox default configuration setting was changed

Answer: B


NEW QUESTION # 41
A company using PaaS to host and develop their software application is experiencing a DOS attack. What challenge will a DFIR analyst experience when investigating this attack?

  • A. Network logs are unavailable for review
  • B. Restricted access to their application logs
  • C. Resource scaling will affect access to logs
  • D. Network monitoring disabled by the company

Answer: A


NEW QUESTION # 42
What Pub/Sub component is used to forward GCP logs to their final location?

  • A. Publication
  • B. Topic
  • C. Log Sink
  • D. Subscription

Answer: C


NEW QUESTION # 43
After registering the application in Azure AD, what is the next step to take in order to use Microsoft Graph API?

  • A. Request access tokens from Azure An
  • B. Call the Graph API
  • C. Get Microsoft 365 global admin approval
  • D. Configure app permission

Answer: D


NEW QUESTION # 44
At what point of the OAuth delegation process does the Resource Owner approve the scope of access to be allowed?

  • A. When the Resource Server receives the OAuth token
  • B. Before user credentials are sent to the Authentication Server
  • C. After user credentials are accepted by the Authorization Server
  • D. Once the OAuth token is accepted by the Application

Answer: C


NEW QUESTION # 45
Which of the following actions described below would populate the suggestions table on an Android phone?

  • A. Google Maps tracks previously entered destinations by the user
  • B. The table contains previously saved or bookmarked destinations
  • C. Google Maps recommends locations, which are cached in the table

Answer: A


NEW QUESTION # 46
A threat actor conducts brute force attacks against SSH services to gain Initial access. This attack technique falls under which category of the Google Workspace MITRE ATT&CK matrix?

  • A. Discovery
  • B. Credential access
  • C. Collection
  • D. Defense evasion

Answer: B


NEW QUESTION # 47
Which cloud service provider produces sampled flow logs?

  • A. AWS
  • B. Azure
  • C. GCP

Answer: C


NEW QUESTION # 48
At which level of an Azure cloud deployment are resource management logs generated?

  • A. Tenant
  • B. Management Group
  • C. Subscription
  • D. Resource Group

Answer: D


NEW QUESTION # 49
Which of the following operating systems are used by Blackberry 10 and found in some vehicles and medical devices?

  • A. QNX
  • B. POSIX
  • C. UNIX
  • D. Bada

Answer: A


NEW QUESTION # 50
Where are iOS Class keys stored?

  • A. In effacable storage
  • B. Between the flash memory and the system area on the device
  • C. In iCloud
  • D. Within the metadata of each file

Answer: D


NEW QUESTION # 51
Which AWS Storage option is ideal for storing incident response related artifacts and logs?

  • A. Simple Storage Service
  • B. Elastic File Store
  • C. ElastiCache
  • D. Elastic Block Storage

Answer: A


NEW QUESTION # 52
An analyst successfully authenticated to Microsoft 365 using the following command. What would cause the analyst to be unable to search UAL events for a specific time period?
Ps> connect fxrhangeOnline userPrincipalName sysanalystatexanpteco.com

  • A. The UAL cannot be searched when using Microsoft 365 PowerShell
  • B. The tmdlets to search the UAl were not Imported into the session
  • C. The ExchangeOnlineManagement module was not installed
  • D. The incorrect version of the FxhangeOnlineManagement module was installed

Answer: B


NEW QUESTION # 53
How is storage account, cs21003200042c87633, created in an Azure resource group?

  • A. Azure CLI was used from a Windows machine
  • B. PowerShelI Cloud Shell was used
  • C. A Bash Cloud Shell was used
  • D. PowerShell Cloud Shell audit logging was enabled

Answer: C


NEW QUESTION # 54
Access Kibana via http://10.0.1.7:5601 and use the *ws-* index pattern. Use the time range 2021-03-01 00:00 UTC to 2021 04 U 00:00 UTC. How many ec2 DescribMnstantp*; events were performed by the root user?

  • A. 0
  • B. 1
  • C. 2, 399
  • D. 2
  • E. 3
  • F. 4
  • G. 6,695
  • H. 5
  • I. 6
  • J. 7

Answer: B


NEW QUESTION # 55
......

Free GCFR Exam Files Downloaded Instantly 100% Dumps & Practice Exam: https://www.actual4labs.com/GIAC/GCFR-actual-exam-dumps.html

Updated Verified GCFR dumps Q&As - 100% Pass Guaranteed: https://drive.google.com/open?id=1fjW_JRt_CUgYXlJeuQnAw22PZ3hODlXY

Contact Us

If you have any question please leave me your email address, we will reply and send email to you in 12 hours.

Our Working Time: ( GMT 0:00-15:00 )
From Monday to Saturday

Support: Contact now