10 exam-style questions with answers and explanations, straight from our 1,058-question bank. Tap an answer to check yourself. When you're ready, take the scored version in the free practice test.
These 10 free GCFR questions are organized by exam domain, so you can see how each part of the GIAC Cloud Forensics Responder (GCFR) blueprint is tested. Reveal the answer and explanation under each question.
Domain 1: Accessing and Investigating Google Workspace Evidence
Question 1
An investigator must determine which IAM principal downloaded a specific object from an S3 bucket three weeks ago. The account has a CloudTrail trail configured with default settings, and the trail is confirmed to be logging and delivering to S3. What is the MOST likely outcome?
Show answer & explanation
Correct answer: B - The GetObject event was not recorded, because S3 data events are not enabled by default
Question 2
A compromised EC2 instance is actively communicating with a command-and-control server. The incident response plan requires preservation of volatile memory. Which action should be performed FIRST?
Show answer & explanation
Correct answer: D - Apply a restrictive security group while leaving the instance running
Question 3
A forensic team is given an EBS snapshot that was shared from a compromised production account into their dedicated forensic account. The snapshot appears in their account, but they cannot create a volume from it. What is the MOST likely cause?
Show answer & explanation
Correct answer: B - The snapshot is encrypted and the KMS key was not also shared with the account
Domain 2: AWS Networking, VMs, and Storage
Question 4
A user's Microsoft 365 mailbox continues to be accessed by an attacker after the account password was reset and MFA was enrolled. Sign-in logs show no suspicious interactive sign-ins during the period of continued access. Which technique is MOST consistent with this behavior?
Show answer & explanation
Correct answer: C - An illicit consent grant to an attacker-registered OAuth application
Question 5
An investigation begins 40 days after a suspected account compromise. The tenant is licensed with Microsoft Entra ID P1. No diagnostic settings, Log Analytics workspace, or Sentinel integration were ever configured. What sign-in log data is available for the compromise window?
Show answer & explanation
Correct answer: A - None - Entra ID sign-in logs are retained for 30 days with P1 licensing
Question 6
An attacker with Contributor rights on an Azure subscription executes code on a virtual machine using the Run Command feature. The investigator reviews the Azure Activity Log. What can be determined?
Show answer & explanation
Correct answer: A - That Run Command was invoked, but not the content of the command that executed
Domain 3: Google Cloud Overview and IAM
Question 7
A Google Cloud project has never had its audit logging configuration modified from the defaults. For which service will data-plane read activity be available to the investigator?
Show answer & explanation
Correct answer: A - BigQuery
Question 8
During a Google Cloud review, an analyst finds a Cloud Storage bucket with the role roles/storage.objectViewer granted to allAuthenticatedUsers. What is the security impact?
Show answer & explanation
Correct answer: B - Any authenticated Google account holder on the internet can read the objects
Domain 4: Google Cloud Storage and Networking
Question 9
While reviewing Kubernetes API server audit logs, an analyst finds an entry with verb set to "create" and objectRef.resource set to "pods/exec". What does this entry MOST directly indicate?
Show answer & explanation
Correct answer: A - A user obtained an interactive shell inside a running container
Domain 5: Google Cloud Virtual Machines
Question 10
An organization suffers a business email compromise in a SaaS email platform. Leadership asks the DFIR team to acquire a forensic image of the mail server. What is the correct response?
Show answer & explanation
Correct answer: C - Imaging is not possible; the investigation depends on audit logs and API data