
GIAC Cloud Security Architecture and Design
Domain 3Objective 3
Key Management Architecture GCAD Practice Questions (Page 5)
Part of the Data Protection and Security domain, which makes up ~19% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–15 in this domain), expect 3–4 from this objective — we provide 30 practice questions to prepare you well beyond it. (estimate)
30questions here
6free pages
7concepts
Questions 21–25
- 21
What is the primary purpose of auditing key usage in a key management system?
Select an answer first - 22
In a cloud environment, what does 'customer-managed key' typically mean?
Select an answer first - 23
What is the recommended method for destroying a cryptographic key that is no longer needed?
Select an answer first - 24
What is the primary purpose of a hardware security module (HSM) in key management?
Select an answer first - 25
A company is designing a key lifecycle process for a new cloud application. The security team must ensure that keys are generated securely, distributed only to authorized services, rotated regularly, and destroyed when no longer needed. The compliance team requires a complete audit trail of all key operations. Which process should the company implement?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCAD” is a trademark of its owner, used for identification only.