Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Cloud Security Essentials

Domain 1Objective 3

Frameworks for Built-In Security GCLD Practice Questions (Page 1)

Part of the Cloud Fundamentals and Shared Responsibility domain, which makes up ~24% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~12–19 in this domain), expect 3–5 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)

33questions here
7free pages
3concepts

Questions 1–5

  1. 1application · medium

    A company is moving its on-premises customer database to a cloud provider. The security team must demonstrate compliance with a framework that provides a common baseline of security controls. They want to use the framework to map which controls are the provider's responsibility and which are the customer's. Which framework is best suited for this purpose?

    Select an answer first
  2. 2expert · hard

    An organization is using a cloud provider's managed database service and needs to implement a control to protect sensitive data. They are using the CSA Cloud Controls Matrix as a guide. Which control should they implement to meet the CCM's data security requirements?

    Select an answer first
  3. 3application · medium

    A company is using a cloud provider's PaaS service to host a web application. They are required to implement a control to protect against SQL injection attacks. According to the shared responsibility model, which control should the customer implement?

    Select an answer first
  4. 4expert · hard

    A security team is using the NIST Cybersecurity Framework to improve their cloud security posture. They have identified a gap in their ability to detect anomalous behavior in their cloud environment. They have budget constraints and need to implement a control that provides the most immediate improvement. Which control should they prioritize?

    Select an answer first
  5. 5application · medium

    A security team is using the CSA Cloud Controls Matrix to assess a new cloud deployment. They need to verify that the provider's data encryption controls meet the organization's requirements. Which document should they review to understand the provider's responsibilities and the controls they implement?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCLD” is a trademark of its owner, used for identification only.