
GIAC AI Security Automation Engineer
Domain 2Objective 1
AWS Cloud Security and Incident Response Automation GASAE Practice Questions (Page 6)
Part of the Cloud Security Automation domain, which makes up ~21% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–25 in this domain), expect 8–13 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)
49questions here
10free pages
15concepts
Questions 26–30
- 26
A company requires that all S3 buckets use server-side encryption with AWS KMS (SSE-KMS). They want to automate the rotation of the KMS keys used for S3 encryption. What is the most appropriate way to achieve this?
Select an answer first - 27
A company uses AWS Systems Manager Incident Manager to manage their incident response. They have integrated Security Hub with Incident Manager so that critical findings automatically create incidents. The on-call engineer wants to receive a notification and be able to see the details of the finding in the incident. What should the engineer configure to ensure this happens?
Select an answer first - 28
A security team wants to detect suspicious network traffic from an EC2 instance, such as communication with a known malicious IP address. They want to automate a response that blocks the traffic by updating the instance's security group to deny all outbound traffic. The detection should be based on VPC Flow Logs. Which approach should be used?
Select an answer first - 29
A company uses AWS Organizations and has GuardDuty enabled in the management account. They want to automate the response to GuardDuty findings across all member accounts. The security team plans to use a Lambda function in the management account that assumes a role in each member account to perform remediation. What is the correct way to grant the Lambda function the necessary permissions?
Select an answer first - 30
A security engineer is automating incident response for a multi-account AWS environment. When GuardDuty detects a compromised IAM role, an EventBridge rule triggers a Lambda function that must revoke the role's permissions and notify the security team. The Lambda function needs to assume a role in each member account to perform the remediation. What is the most secure way to grant the Lambda function the necessary cross-account permissions?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GASAE” is a trademark of its owner, used for identification only.