
GIAC Certified Incident Handler
Domain 4Objective 3
Securing Credentials and Data in the Cloud GCIH Practice Questions (Page 2)
Part of the Credential and Access Security domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~17–29 in this domain), expect 6–10 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
10concepts
Questions 6–10
- 6
A security analyst is investigating a potential cloud credential compromise. The analyst sees that a service account key was used to access a sensitive database, but the key was rotated 24 hours ago. The analyst also notices that the service account has a policy that allows it to create new keys. What is the most likely explanation for the continued use of the old key?
Select an answer first - 7
Which of the following best describes a temporary token used in cloud environments?
Select an answer first - 8
A company stores sensitive documents in a cloud storage bucket. The compliance team requires that only specific users can access the bucket and that all access is logged. The bucket currently has a public-read policy. What is the most secure configuration?
Select an answer first - 9
What is a key step in the lifecycle management of a cloud credential when an employee leaves the organization?
Select an answer first - 10
A large organization is migrating to a cloud environment and needs to manage credentials for both human users and automated workloads. The security team wants to avoid long-lived credentials for workloads and enforce MFA for all human users. However, some legacy workloads cannot use workload identity federation. What is the most secure approach to manage credentials for the legacy workloads?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIH” is a trademark of its owner, used for identification only.