
Latest GIAC GCFR Practice Test Questions, GIAC Cloud Forensics Responder (GCFR) Exam Dumps
Aug-2024 Pass GIAC GCFR Exam in First Attempt Easily
NEW QUESTION # 38
Which Azure blob storage option is typically used to store virtual hard drive (VHD) Ales?
- A. File
- B. page
- C. Block
- D. Append
Answer: B
NEW QUESTION # 39
What AWS service will allow an organization to set custom compliance metrics and force compliance on an organizational, sub-organizational, or individual account level?
- A. Security Hub
- B. Inspector
- C. Cognllo
- D. Config
Answer: D
NEW QUESTION # 40
An investigator confirms that phishing emails sent to users in an organization ate not being sent to their Gmall Spam folder. What is a possible cause for this?
- A. Compliance based rules need to be configured to detect phishing emails
- B. The default setting for enhanced pre-delivery message scanning was changed
- C. A third party application needs to be installed to detect phishing emails
- D. The security sandbox default configuration setting was changed
Answer: B
NEW QUESTION # 41
A company using PaaS to host and develop their software application is experiencing a DOS attack. What challenge will a DFIR analyst experience when investigating this attack?
- A. Network logs are unavailable for review
- B. Restricted access to their application logs
- C. Resource scaling will affect access to logs
- D. Network monitoring disabled by the company
Answer: A
NEW QUESTION # 42
What Pub/Sub component is used to forward GCP logs to their final location?
- A. Publication
- B. Topic
- C. Log Sink
- D. Subscription
Answer: C
NEW QUESTION # 43
After registering the application in Azure AD, what is the next step to take in order to use Microsoft Graph API?
- A. Request access tokens from Azure An
- B. Call the Graph API
- C. Get Microsoft 365 global admin approval
- D. Configure app permission
Answer: D
NEW QUESTION # 44
At what point of the OAuth delegation process does the Resource Owner approve the scope of access to be allowed?
- A. When the Resource Server receives the OAuth token
- B. Before user credentials are sent to the Authentication Server
- C. After user credentials are accepted by the Authorization Server
- D. Once the OAuth token is accepted by the Application
Answer: C
NEW QUESTION # 45
Which of the following actions described below would populate the suggestions table on an Android phone?
- A. Google Maps tracks previously entered destinations by the user
- B. The table contains previously saved or bookmarked destinations
- C. Google Maps recommends locations, which are cached in the table
Answer: A
NEW QUESTION # 46
A threat actor conducts brute force attacks against SSH services to gain Initial access. This attack technique falls under which category of the Google Workspace MITRE ATT&CK matrix?
- A. Discovery
- B. Credential access
- C. Collection
- D. Defense evasion
Answer: B
NEW QUESTION # 47
Which cloud service provider produces sampled flow logs?
- A. AWS
- B. Azure
- C. GCP
Answer: C
NEW QUESTION # 48
At which level of an Azure cloud deployment are resource management logs generated?
- A. Tenant
- B. Management Group
- C. Subscription
- D. Resource Group
Answer: D
NEW QUESTION # 49
Which of the following operating systems are used by Blackberry 10 and found in some vehicles and medical devices?
- A. QNX
- B. POSIX
- C. UNIX
- D. Bada
Answer: A
NEW QUESTION # 50
Where are iOS Class keys stored?
- A. In effacable storage
- B. Between the flash memory and the system area on the device
- C. In iCloud
- D. Within the metadata of each file
Answer: D
NEW QUESTION # 51
Which AWS Storage option is ideal for storing incident response related artifacts and logs?
- A. Simple Storage Service
- B. Elastic File Store
- C. ElastiCache
- D. Elastic Block Storage
Answer: A
NEW QUESTION # 52
An analyst successfully authenticated to Microsoft 365 using the following command. What would cause the analyst to be unable to search UAL events for a specific time period?
Ps> connect fxrhangeOnline userPrincipalName sysanalystatexanpteco.com
- A. The UAL cannot be searched when using Microsoft 365 PowerShell
- B. The tmdlets to search the UAl were not Imported into the session
- C. The ExchangeOnlineManagement module was not installed
- D. The incorrect version of the FxhangeOnlineManagement module was installed
Answer: B
NEW QUESTION # 53
How is storage account, cs21003200042c87633, created in an Azure resource group?
- A. Azure CLI was used from a Windows machine
- B. PowerShelI Cloud Shell was used
- C. A Bash Cloud Shell was used
- D. PowerShell Cloud Shell audit logging was enabled
Answer: C
NEW QUESTION # 54
Access Kibana via http://10.0.1.7:5601 and use the *ws-* index pattern. Use the time range 2021-03-01 00:00 UTC to 2021 04 U 00:00 UTC. How many ec2 DescribMnstantp*; events were performed by the root user?
- A. 0
- B. 1
- C. 2, 399
- D. 2
- E. 3
- F. 4
- G. 6,695
- H. 5
- I. 6
- J. 7
Answer: B
NEW QUESTION # 55
......
Free GCFR Exam Files Downloaded Instantly 100% Dumps & Practice Exam: https://www.actual4labs.com/GIAC/GCFR-actual-exam-dumps.html
Updated Verified GCFR dumps Q&As - 100% Pass Guaranteed: https://drive.google.com/open?id=1fjW_JRt_CUgYXlJeuQnAw22PZ3hODlXY