
GIAC Cloud Security Architecture and Design
Domain 3Objective 1
Data Security GCAD Practice Questions (Page 3)
Part of the Data Protection and Security domain, which makes up ~19% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–15 in this domain), expect 3–4 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)
48questions here
10free pages
10concepts
Questions 11–15
- 11
Which access control model grants permissions based on the roles a user holds within an organization?
Select an answer first - 12
In which scenario is tokenization most appropriate?
Select an answer first - 13
A company is moving its data to a public cloud. The company has a strict requirement that encryption keys must be stored on-premises and never leave the company's control. The cloud provider offers a key management service, but the company does not want to use it. The company needs to encrypt data at rest in the cloud. Which approach should they take?
Select an answer first - 14
A US-based company processes personal data of EU citizens and stores it in a cloud region in the United States. The company is subject to GDPR. Which measure is most directly required to comply with GDPR's data transfer rules?
Select an answer first - 15
A company's data loss prevention (DLP) policy prohibits sending credit card numbers via email. An employee uses a web-based email client and attempts to attach a spreadsheet containing a column of credit card numbers. The DLP solution inspects the attachment and blocks the email. Which DLP technique is being used?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCAD” is a trademark of its owner, used for identification only.