GIAC Cloud Forensics Responder (GCFR) Exam Prep
Free practice questions

Free GCFR Practice Questions

10 exam-style questions with answers and explanations, straight from our 1,058-question bank. Tap an answer to check yourself. When you're ready, take the scored version in the free practice test.

Start the free practice test → ★★★★★4.9/5 from 2,400+ candidates · No signup

The GCFR exam has 82 questions and runs 3 hours.

These 10 free GCFR questions are organized by exam domain, so you can see how each part of the GIAC Cloud Forensics Responder (GCFR) blueprint is tested. Reveal the answer and explanation under each question.

Domain 1: Accessing and Investigating Google Workspace Evidence

Question 1

An investigator must determine which IAM principal downloaded a specific object from an S3 bucket three weeks ago. The account has a CloudTrail trail configured with default settings, and the trail is confirmed to be logging and delivering to S3. What is the MOST likely outcome?

Show answer & explanation

Correct answer: B - The GetObject event was not recorded, because S3 data events are not enabled by default

Question 2

A compromised EC2 instance is actively communicating with a command-and-control server. The incident response plan requires preservation of volatile memory. Which action should be performed FIRST?

Show answer & explanation

Correct answer: D - Apply a restrictive security group while leaving the instance running

Question 3

A forensic team is given an EBS snapshot that was shared from a compromised production account into their dedicated forensic account. The snapshot appears in their account, but they cannot create a volume from it. What is the MOST likely cause?

Show answer & explanation

Correct answer: B - The snapshot is encrypted and the KMS key was not also shared with the account

Domain 2: AWS Networking, VMs, and Storage

Question 4

A user's Microsoft 365 mailbox continues to be accessed by an attacker after the account password was reset and MFA was enrolled. Sign-in logs show no suspicious interactive sign-ins during the period of continued access. Which technique is MOST consistent with this behavior?

Show answer & explanation

Correct answer: C - An illicit consent grant to an attacker-registered OAuth application

Question 5

An investigation begins 40 days after a suspected account compromise. The tenant is licensed with Microsoft Entra ID P1. No diagnostic settings, Log Analytics workspace, or Sentinel integration were ever configured. What sign-in log data is available for the compromise window?

Show answer & explanation

Correct answer: A - None - Entra ID sign-in logs are retained for 30 days with P1 licensing

Question 6

An attacker with Contributor rights on an Azure subscription executes code on a virtual machine using the Run Command feature. The investigator reviews the Azure Activity Log. What can be determined?

Show answer & explanation

Correct answer: A - That Run Command was invoked, but not the content of the command that executed

Domain 3: Google Cloud Overview and IAM

Question 7

A Google Cloud project has never had its audit logging configuration modified from the defaults. For which service will data-plane read activity be available to the investigator?

Show answer & explanation

Correct answer: A - BigQuery

Question 8

During a Google Cloud review, an analyst finds a Cloud Storage bucket with the role roles/storage.objectViewer granted to allAuthenticatedUsers. What is the security impact?

Show answer & explanation

Correct answer: B - Any authenticated Google account holder on the internet can read the objects

Domain 4: Google Cloud Storage and Networking

Question 9

While reviewing Kubernetes API server audit logs, an analyst finds an entry with verb set to "create" and objectRef.resource set to "pods/exec". What does this entry MOST directly indicate?

Show answer & explanation

Correct answer: A - A user obtained an interactive shell inside a running container

Domain 5: Google Cloud Virtual Machines

Question 10

An organization suffers a business email compromise in a SaaS email platform. Leadership asks the DFIR team to acquire a forensic image of the mail server. What is the correct response?

Show answer & explanation

Correct answer: C - Imaging is not possible; the investigation depends on audit logs and API data

The rest of the GCFR blueprint

The GCFR exam also covers these domains. Drill them in the full free practice test:

That's 10 of 1,058

The full bank has 1,048 more GCFR questions with explanations.

Continue in the free practice test →

View plans