Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Cloud Security Architecture and Design

Domain 1Objective 1

Cloud Identity GCAD Practice Questions (Page 3)

Part of the Identity and Access Management domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–23 in this domain), expect 3–5 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)

40questions here
8free pages
5concepts

Questions 11–15

  1. 11application · medium

    A company is migrating to a cloud-based identity provider (IdP) and wants to maintain SSO with their on-premises applications that use LDAP. The IdP supports SAML and OIDC, but the on-premises apps only support LDAP. What should the company do to enable SSO for these apps?

    Select an answer first
  2. 12application · medium

    An organization uses a cloud identity provider (IdP) to manage access to a project management tool. A contractor's contract is ending, and the administrator needs to ensure the contractor can no longer access the tool. Which action should be taken first?

    Select an answer first
  3. 13application · medium

    An organization uses a cloud identity platform to provision users into Google Workspace and GitHub. When a contractor's contract is extended, the HR system updates the end date. The identity platform is configured to disable the user on the end date. What is the primary benefit of this automated lifecycle management?

    Select an answer first
  4. 14application · medium

    An organization uses a cloud identity provider (IdP) to manage access to multiple SaaS applications. The IT team wants to automate the creation of user accounts in the IdP when new employees are hired, and automatically remove them when they leave. Which approach should they use?

    Select an answer first
  5. 15application · medium

    A company uses Azure AD as its identity provider and has enabled federation with an on-premises Active Directory. Users access a cloud HR application via SAML SSO. The security team wants to require MFA for all cloud app access, but the on-premises AD does not support MFA. What is the most effective way to enforce MFA?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCAD” is a trademark of its owner, used for identification only.