
GIAC Certified Incident Handler
Domain 4Objective 3
Securing Credentials and Data in the Cloud GCIH Practice Questions (Page 6)
Part of the Credential and Access Security domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~17–29 in this domain), expect 6–10 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
10concepts
Questions 26–30
- 26
An organization has a policy to rotate cloud access keys every 60 days. A critical application uses an access key that is embedded in a configuration file and cannot be updated without a maintenance window. The key is 75 days old. The security team is concerned about the risk of compromise. What is the best approach to manage this risk?
Select an answer first - 27
A security analyst notices unusual activity in the cloud environment: an access key that is normally used only during business hours is being used at 3:00 AM from an unfamiliar IP address. The analyst suspects the key has been compromised. What is the most immediate action the analyst should take?
Select an answer first - 28
Why is it important to avoid hardcoding cloud credentials in application code?
Select an answer first - 29
Why is it recommended to use a cloud KMS rather than storing encryption keys in application code?
Select an answer first - 30
A cloud administrator is creating an IAM policy for a new application that only needs to read from a specific storage bucket and write logs to a specific log group. The application runs on a compute instance. What is the most appropriate IAM policy design?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIH” is a trademark of its owner, used for identification only.