
GIAC Cloud Security Architecture and Design
Domain 1Objective 5
Architecting Cross-Cloud Identity GCAD Practice Questions (Page 5)
Part of the Identity and Access Management domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–23 in this domain), expect 3–5 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)
32questions here
7free pages
8concepts
Questions 21–25
- 21
A company has a web application hosted in AWS that needs to authenticate users from a partner organization using their own identity system. The partner uses a legacy identity provider that only supports SAML. The application currently supports OIDC. What is the most appropriate way to enable this integration?
Select an answer first - 22
An organization uses Azure AD as its identity source and is adopting Google Cloud. They need to ensure that user attributes like 'cost center' are available in Google Cloud for resource labeling and access decisions. The organization wants to avoid manual data entry. What should they implement?
Select an answer first - 23
Which identity provider (IdP) strategy involves using a single IdP as the authoritative source for all user identities and having each cloud provider trust that IdP?
Select an answer first - 24
In a federated identity model, what is the role of the identity provider (IdP) in relation to a cloud service provider (SP)?
Select an answer first - 25
What is a primary advantage of using multiple identity providers (IdPs) in a cross-cloud architecture?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCAD” is a trademark of its owner, used for identification only.