Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Cloud Security Architecture and Design

Domain 3Objective 1

Data Security GCAD Practice Questions (Page 5)

Part of the Data Protection and Security domain, which makes up ~19% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–15 in this domain), expect 3–4 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)

48questions here
10free pages
10concepts

Questions 21–25

  1. 21foundation · easy

    Which regulation specifically addresses the protection of personal data of individuals in the European Union?

    Select an answer first
  2. 22application · medium

    A healthcare SaaS provider needs to share a production database with a third-party analytics vendor for a one-time research project. The vendor must see realistic patient data to build models, but the data cannot leave the provider's cloud environment, and the vendor must not be able to reverse-engineer actual patient identities. The provider has already classified the data as 'Restricted' under its data classification policy. Which approach best satisfies the vendor's need while protecting patient privacy?

    Select an answer first
  3. 23expert · hard

    A company has a cloud storage bucket containing files classified as 'Confidential'. The security team wants to implement least privilege access. Currently, all employees have read/write access to the bucket. The team needs to ensure that only the data owners can modify files, while other employees can only read files they are explicitly granted access to. The company uses an identity provider with group membership. Which access control approach best meets this requirement?

    Select an answer first
  4. 24expert · hard

    A company is designing a cloud application that processes highly sensitive data. The security team wants to protect the data while it is being processed in memory. The data is currently encrypted at rest and in transit. Which additional control should the company implement to protect data in use?

    Select an answer first
  5. 25foundation · easy

    Which data classification label would typically be applied to information whose unauthorized disclosure could cause serious harm to an organization, such as customer financial records?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCAD” is a trademark of its owner, used for identification only.