Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS)

GIAC Cloud Security Essentials

GCLD

The GIAC Cloud Security Essentials (GCLD) certification validates a practitioner's ability to secure cloud-based workloads across the full cloud security landscape. It proves you can implement preventive, detective, and reactionary techniques to defend valuable assets in single and multi-cloud environments. Ideal for security engineers, analysts, and administrators responsible for securing cloud environments, this credential demonstrates fluency in the unique challenges of cloud security.

636 practice questions · Updated 2026-07-30

6Domains
16Objectives
101Concepts
636Questions

GCLD Curriculum

Every domain, objective, and concept the GCLD exam measures.

Cloud Account Fundamentals

7 concepts · 36 questions
  1. Cloud Account Creation
  2. Account Structure and Hierarchy
  3. Identity and Access Management (IAM) Basics
  4. Billing and Cost Management
  5. Account Security Best Practices
  6. Shared Responsibility Model in Account Context
  7. Account Governance and Compliance
  1. Shared Responsibility Model
  2. Threat Informed Defense

Frameworks for Built-in Security

3 concepts · 33 questions
  1. Identify common cloud security frameworks
  2. Map frameworks to cloud shared responsibility
  3. Apply frameworks to cloud architecture

Risk Management and Compliance

5 concepts · 46 questions
  1. Shared Responsibility Model
  2. Cloud Risk Assessment
  3. Compliance Frameworks and Standards
  4. Compliance in Cloud Services
  5. Risk Management Strategies

Cloud Networking Technology

10 concepts · 31 questions
  1. Cloud Network Architecture
  2. Virtual Private Cloud (VPC)
  3. Subnets and CIDR
  4. Routing and Gateways
  5. Security Groups and Network ACLs
  6. Load Balancing
  7. DNS and Cloud DNS
  8. VPN and Direct Connect
  9. Peering and Transit
  10. Cloud Network Monitoring

Securing Cloud Networks

7 concepts · 29 questions
  1. Cloud Network Security Fundamentals
  2. Virtual Network Segmentation
  3. Security Groups and Firewall Rules
  4. Cloud Network Encryption
  5. Secure Network Access Controls
  6. Monitoring and Logging for Cloud Networks
  7. Cloud Network Hardening
  1. Cloud Network Monitoring Fundamentals
  2. Cloud Traffic Capture Methods
  3. Monitoring Tools and Services
  4. Anomaly Detection and Alerting
  5. Incident Response and Forensics

External access and IAM Best Practices

6 concepts · 44 questions
  1. External Access Models
  2. IAM Best Practices for External Users
  3. Federated Identity for External Access
  4. Temporary Credentials for External Access
  5. External Access Policies
  6. Monitoring and Auditing External Access

Secrets Management

10 concepts · 51 questions
  1. Secrets Management Fundamentals
  2. Secrets Lifecycle Management
  3. Centralized Secrets Storage
  4. Secrets Access Control
  5. Secrets Rotation and Versioning
  6. Secrets Encryption at Rest and in Transit
  7. Integration with Applications and Services
  8. Auditing and Monitoring Secrets Usage
  9. Secrets in CI/CD Pipelines
  10. Incident Response for Secrets Compromise

Secure Compute Deployment

7 concepts · 31 questions
  1. Secure compute deployment principles
  2. Hardening compute instances
  3. Secure access control for compute
  4. Encryption for compute storage
  5. Monitoring and logging for compute
  6. Secure instance metadata and credentials
  7. Compliance and governance for compute

Containers and Cloud Storage

6 concepts · 40 questions
  1. Container Fundamentals
  2. Container Orchestration
  3. Container Security
  4. Cloud Storage Types
  5. Storage Security
  6. Storage Performance and Cost

Discovering and Storing Sensitive Data

9 concepts · 51 questions
  1. Sensitive Data Discovery
  2. Data Classification
  3. Data Storage Options
  4. Encryption at Rest
  5. Key Management
  6. Data Retention and Deletion
  7. Access Controls for Sensitive Data
  8. Data Loss Prevention (DLP)
  9. Automation of Data Protection

Using Sensitive Data

10 concepts · 53 questions
  1. Sensitive Data Identification
  2. Data Classification
  3. Data Discovery
  4. Data Inventory and Mapping
  5. Data Loss Prevention (DLP)
  6. Encryption for Sensitive Data
  7. Access Control for Sensitive Data
  8. Data Masking and Redaction
  9. Compliance and Regulatory Requirements
  10. Monitoring and Auditing Sensitive Data

Cloud Automation

7 concepts · 45 questions
  1. Cloud Automation Fundamentals
  2. Infrastructure as Code (IaC)
  3. Configuration Management
  4. CI/CD Pipelines
  5. Automated Security Controls
  6. Automation Tools and Services
  7. Automation Best Practices

Cloud Logging Fundamentals

1 concepts · 36 questions
  1. Cloud Logging Fundamentals
  1. Cloud Attack Vectors
  2. Cloud Intrusion Detection
  3. Incident Response in the Cloud
  4. Cloud Forensics
  5. Logging and Monitoring for Cloud Security
  6. Responding to Cloud-Specific Threats
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.

Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for GCLD, so none is invented.