Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Cloud Security Architecture and Design

Domain 3Objective 2

Defending Data in the Cloud GCAD Practice Questions (Page 5)

Part of the Data Protection and Security domain, which makes up ~19% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–15 in this domain), expect 3–4 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)

28questions here
6free pages
8concepts

Questions 21–25

  1. 21application · medium

    A healthcare organization stores patient records in an Azure Blob Storage account. Compliance requires that only authorized clinical staff can access records containing protected health information (PHI), while administrative staff can access non-PHI operational documents stored in the same account. The organization uses Azure Active Directory (Azure AD) for identity. Which combination of controls should the organization implement?

    Select an answer first
  2. 22application · medium

    A government agency is required to retain email records for seven years and then securely delete them. The agency uses Microsoft 365 Exchange Online. The compliance officer wants to ensure that emails are not permanently deleted before the retention period ends, and that after seven years they are purged in a way that meets the agency's secure disposal policy. Which solution should the security architect implement?

    Select an answer first
  3. 23expert · hard

    A global bank must store customer data for EU residents in the EU to comply with GDPR data residency requirements. The bank uses AWS and currently stores data in us-east-1. The security architect is tasked with moving the data to an EU region. The bank also requires that encryption keys be managed by the bank and stored in the EU. Which approach best satisfies both requirements?

    Select an answer first
  4. 24foundation · easy

    Which cloud access control mechanism is used to grant a specific user read-only access to a single object in a cloud storage bucket?

    Select an answer first
  5. 25foundation · easy

    A cloud security architect is defining data classification levels for a new cloud environment. Which classification level is typically used for data that, if exposed, could cause significant harm to the organization but is not intended for public release?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCAD” is a trademark of its owner, used for identification only.