Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Cloud Security Architecture and Design

Domain 1Objective 5

Architecting Cross-Cloud Identity GCAD Practice Questions (Page 4)

Part of the Identity and Access Management domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–23 in this domain), expect 3–5 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)

32questions here
7free pages
8concepts

Questions 16–20

  1. 16application · medium

    A company has two separate business units that each use a different identity provider (Okta and Microsoft Entra ID). They are consolidating their cloud workloads and want to maintain the existing IdPs while providing a unified access experience for users. What is the recommended approach?

    Select an answer first
  2. 17foundation · easy

    Which standard is specifically designed for exchanging authentication and authorization data between an identity provider and a service provider using XML-based assertions?

    Select an answer first
  3. 18application · medium

    A company uses a central identity provider and wants to allow users to access resources in both AWS and Azure using the same credentials. They have configured SAML federation with AWS and OIDC federation with Azure. What is the key requirement for establishing trust between the identity provider and each cloud?

    Select an answer first
  4. 19expert · hard

    A company has two identity providers: one for employees and one for customers. They are architecting a cross-cloud identity solution and want to provide employees with access to internal applications in AWS and Azure, while customers access a public-facing application in Azure. The security team wants to minimize the attack surface and ensure that customer identities cannot access internal resources. Which strategy should be recommended?

    Select an answer first
  5. 20application · medium

    A company is migrating workloads from on-premises to both AWS and Azure. They currently use a single on-premises Active Directory. The security team wants to ensure that user access to cloud resources is governed by the same policies as on-premises. Which challenge is most critical to address when architecting cross-cloud identity?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCAD” is a trademark of its owner, used for identification only.