
GIAC Cloud Security Architecture and Design
Domain 1Objective 2
Customer Identity and Access Management GCAD Practice Questions (Page 6)
Part of the Identity and Access Management domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–23 in this domain), expect 3–5 from this objective — we provide 52 practice questions to prepare you well beyond it. (estimate)
52questions here
11free pages
10concepts
Questions 26–30
- 26
A B2B software company provides a customer portal where each customer organization has an admin who manages its users. The company wants to ensure that a customer admin cannot accidentally or maliciously grant themselves access to another customer organization's data. Which authorization design is most appropriate?
Select an answer first - 27
A mobile app company operating in California must comply with CCPA. The app collects customer location data for personalized recommendations. The product team wants to enable this feature by default. The legal team requires opt-in consent. What is the correct CIAM configuration?
Select an answer first - 28
A media streaming service wants to allow users to sign in with their existing Google or Facebook accounts. The service also needs to enforce different content access levels based on the user's subscription tier. Which architecture best supports this requirement?
Select an answer first - 29
A company is integrating a CIAM platform with a legacy on-premises application that only supports SAML 2.0. The CIAM platform natively supports OIDC and SAML. The application must authenticate customers who log in via social providers (Google, Facebook). The security team requires that the application never sees the customer's social provider credentials. Which integration approach is correct?
Select an answer first - 30
A financial services company notices a spike in account takeover (ATO) attempts against customer accounts. The attacks use previously breached passwords. The CIAM team wants to implement a control that directly addresses this attack vector without requiring customers to change their password immediately. Which control is most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCAD” is a trademark of its owner, used for identification only.