
GIAC Cloud Security Architecture and Design
Domain 1Objective 5
Architecting Cross-Cloud Identity GCAD Practice Questions (Page 2)
Part of the Identity and Access Management domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–23 in this domain), expect 3–5 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)
32questions here
7free pages
8concepts
Questions 6–10
- 6
A multinational company uses a central identity provider and synchronizes user attributes to both AWS and Azure. They must comply with GDPR, which requires that personal data of EU citizens be processed in the EU. The company has offices in the EU and the US. Users in the EU access resources in both AWS and Azure. What is the most important consideration when architecting this cross-cloud identity solution?
Select an answer first - 7
When establishing a trust relationship between a cloud service provider (SP) and an external identity provider (IdP), which of the following is typically exchanged to enable the SP to validate assertions from the IdP?
Select an answer first - 8
When architecting cross-cloud identity, which security control is essential to protect assertions and tokens exchanged between identity providers and service providers?
Select an answer first - 9
Which of the following is a cross-cloud identity challenge that arises from differences in how cloud providers define and enforce access policies?
Select an answer first - 10
When architecting identity across multiple cloud providers, which of the following is a unique challenge that arises specifically from the use of different cloud providers?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCAD” is a trademark of its owner, used for identification only.