
GIAC Cloud Security Architecture and Design
Domain 3Objective 3
Key Management Architecture GCAD Practice Questions (Page 3)
Part of the Data Protection and Security domain, which makes up ~19% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–15 in this domain), expect 3–4 from this objective — we provide 30 practice questions to prepare you well beyond it. (estimate)
30questions here
6free pages
7concepts
Questions 11–15
- 11
A multinational corporation uses a cloud provider's key management service to store keys for encrypting data in multiple regions. The security team needs to ensure that keys are protected at rest and that access to keys is logged for compliance. The company also wants to minimize the risk of a single region's compromise affecting all keys. Which configuration should the security team implement?
Select an answer first - 12
Why is it important to protect cryptographic keys from unauthorized access?
Select an answer first - 13
Which of the following lists the stages of a cryptographic key's lifecycle in the correct order?
Select an answer first - 14
A government agency is decommissioning an old system that used a custom encryption key to protect archived records. The agency must ensure that the key cannot be used to decrypt the archived data after decommissioning, but the data must be retained for legal purposes. Which action should the agency take?
Select an answer first - 15
Which practice helps ensure that key management practices meet compliance requirements?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCAD” is a trademark of its owner, used for identification only.