
GIAC Cloud Security Essentials
Domain 5Objective 1
Discovering and Storing Sensitive Data GCLD Practice Questions (Page 5)
Part of the Data Protection and Automation domain, which makes up ~23% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~12–18 in this domain), expect 4–6 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)
51questions here
11free pages
9concepts
Questions 21–25
- 21
An e-commerce company must delete customer personal data after 30 days of account closure, but retain transaction records for tax purposes for five years. The data is stored in object storage. Which approach ensures both requirements are met automatically?
Select an answer first - 22
Which of the following is an example of a DLP control that prevents sensitive data from leaving the organization?
Select an answer first - 23
What is the main benefit of automating data protection processes such as discovery, classification, and encryption?
Select an answer first - 24
A company uses a cloud KMS to encrypt data in multiple services. The security team must ensure that only specific applications can decrypt data, while administrators can manage keys but not decrypt data. The team also needs to rotate keys without disrupting applications. Which configuration best meets these requirements?
Select an answer first - 25
A company has a cloud storage bucket that contains sensitive data. The security team wants to ensure that access is monitored and that any unusual access patterns trigger an alert. What should they configure?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCLD” is a trademark of its owner, used for identification only.