
GIAC AI Security Automation Engineer
Domain 2Objective 2
Azure Cloud Security and Incident Response Automation GASAE Practice Questions (Page 5)
Part of the Cloud Security Automation domain, which makes up ~21% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–25 in this domain), expect 8–13 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
10concepts
Questions 21–25
- 21
A security team wants to automate the response to Azure Monitor alerts that indicate a user has signed in from an impossible travel location. They want to disable the user's account in Azure AD and send a notification to the security team. Which service should they use to orchestrate these actions?
Select an answer first - 22
A DevOps team wants to integrate security testing into their CI/CD pipeline. They need to scan infrastructure-as-code templates for misconfigurations, validate that secrets are not hardcoded, and ensure that the deployment uses the latest approved versions of third-party libraries. They also want to fail the pipeline if any critical issue is found. Which solution should they implement?
Select an answer first - 23
A security team wants to automate the response to a specific type of alert from Microsoft Defender for Identity (e.g., suspicious Kerberos activity). They want to automatically isolate the affected user account, reset the password, and notify the user's manager. They also need to ensure that the response is reversible if it was a false positive. Which solution should they implement?
Select an answer first - 24
A company wants to automate the detection and response to data exfiltration attempts from Azure Blob Storage. They want to monitor for unusual download patterns, automatically block the user's access if a threshold is exceeded, and log the event for compliance. They also want to minimize the time between detection and response. Which solution should they implement?
Select an answer first - 25
You want to automatically run a security vulnerability scan on your code every time a developer pushes to the main branch. Which Azure DevOps component should you use to define this automated process?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GASAE” is a trademark of its owner, used for identification only.