
GIAC Certified Incident Handler
Domain 4Objective 3
Securing Credentials and Data in the Cloud GCIH Practice Questions (Page 7)
Part of the Credential and Access Security domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~17–29 in this domain), expect 6–10 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
10concepts
Questions 31–35
- 31
A cloud environment has a service account that is used by multiple applications. The service account currently has a policy that grants full access to all storage buckets and all compute instances. The security team wants to reduce the risk of credential abuse but cannot break the applications. Which approach best balances security and operational continuity?
Select an answer first - 32
Why is regular rotation of cloud credentials important?
Select an answer first - 33
What is the first step in responding to a suspected cloud credential compromise?
Select an answer first - 34
What is the purpose of monitoring credential usage in a cloud environment?
Select an answer first - 35
A development team wants to store database credentials in a cloud secret management service. The security team requires that the credentials be automatically rotated and that access to the secrets be audited. The team also wants to minimize the risk of secrets appearing in logs. Which configuration is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIH” is a trademark of its owner, used for identification only.