
GIAC Certified Incident Handler
Domain 4Objective 3
Securing Credentials and Data in the Cloud GCIH Practice Questions (Page 8)
Part of the Credential and Access Security domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~17–29 in this domain), expect 6–10 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
10concepts
Questions 36–40
- 36
Which of the following is an example of encrypting data at rest in a cloud storage service?
Select an answer first - 37
What is the principle of least privilege in the context of IAM policies?
Select an answer first - 38
A security policy requires that all cloud access keys be rotated every 90 days. An administrator discovers that a critical application uses an access key that was created 120 days ago and the key is embedded in the application's configuration file. What is the best course of action?
Select an answer first - 39
Which configuration is essential for securing a cloud storage bucket that contains sensitive data?
Select an answer first - 40
A security analyst is reviewing cloud logs and notices that a service account key was used to access a storage bucket from an IP address that is not associated with the organization. The key is scheduled for rotation in 30 days. What is the most appropriate immediate response?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIH” is a trademark of its owner, used for identification only.