
GIAC Cloud Security Essentials
The GIAC Cloud Security Essentials (GCLD) certification validates a practitioner's ability to secure cloud-based workloads across the full cloud security landscape. It proves you can implement preventive, detective, and reactionary techniques to defend valuable assets in single and multi-cloud environments. Ideal for security engineers, analysts, and administrators responsible for securing cloud environments, this credential demonstrates fluency in the unique challenges of cloud security.
636 practice questions · Updated 2026-07-30
GCLD Curriculum
Every domain, objective, and concept the GCLD exam measures.
- Cloud Account Creation
- Account Structure and Hierarchy
- Identity and Access Management (IAM) Basics
- Billing and Cost Management
- Account Security Best Practices
- Shared Responsibility Model in Account Context
- Account Governance and Compliance
- Identify common cloud security frameworks
- Map frameworks to cloud shared responsibility
- Apply frameworks to cloud architecture
- Shared Responsibility Model
- Cloud Risk Assessment
- Compliance Frameworks and Standards
- Compliance in Cloud Services
- Risk Management Strategies
- Cloud Network Architecture
- Virtual Private Cloud (VPC)
- Subnets and CIDR
- Routing and Gateways
- Security Groups and Network ACLs
- Load Balancing
- DNS and Cloud DNS
- VPN and Direct Connect
- Peering and Transit
- Cloud Network Monitoring
- Cloud Network Security Fundamentals
- Virtual Network Segmentation
- Security Groups and Firewall Rules
- Cloud Network Encryption
- Secure Network Access Controls
- Monitoring and Logging for Cloud Networks
- Cloud Network Hardening
- Cloud Network Monitoring Fundamentals
- Cloud Traffic Capture Methods
- Monitoring Tools and Services
- Anomaly Detection and Alerting
- Incident Response and Forensics
- External Access Models
- IAM Best Practices for External Users
- Federated Identity for External Access
- Temporary Credentials for External Access
- External Access Policies
- Monitoring and Auditing External Access
- Secrets Management Fundamentals
- Secrets Lifecycle Management
- Centralized Secrets Storage
- Secrets Access Control
- Secrets Rotation and Versioning
- Secrets Encryption at Rest and in Transit
- Integration with Applications and Services
- Auditing and Monitoring Secrets Usage
- Secrets in CI/CD Pipelines
- Incident Response for Secrets Compromise
- Secure compute deployment principles
- Hardening compute instances
- Secure access control for compute
- Encryption for compute storage
- Monitoring and logging for compute
- Secure instance metadata and credentials
- Compliance and governance for compute
- Container Fundamentals
- Container Orchestration
- Container Security
- Cloud Storage Types
- Storage Security
- Storage Performance and Cost
- Sensitive Data Discovery
- Data Classification
- Data Storage Options
- Encryption at Rest
- Key Management
- Data Retention and Deletion
- Access Controls for Sensitive Data
- Data Loss Prevention (DLP)
- Automation of Data Protection
- Sensitive Data Identification
- Data Classification
- Data Discovery
- Data Inventory and Mapping
- Data Loss Prevention (DLP)
- Encryption for Sensitive Data
- Access Control for Sensitive Data
- Data Masking and Redaction
- Compliance and Regulatory Requirements
- Monitoring and Auditing Sensitive Data
- Cloud Automation Fundamentals
- Infrastructure as Code (IaC)
- Configuration Management
- CI/CD Pipelines
- Automated Security Controls
- Automation Tools and Services
- Automation Best Practices
- Cloud Logging Fundamentals
- Cloud Attack Vectors
- Cloud Intrusion Detection
- Incident Response in the Cloud
- Cloud Forensics
- Logging and Monitoring for Cloud Security
- Responding to Cloud-Specific Threats
Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for GCLD, so none is invented.