
GIAC Cloud Security Essentials
Domain 1Objective 3
Frameworks for Built-In Security GCLD Practice Questions (Page 7)
Part of the Cloud Fundamentals and Shared Responsibility domain, which makes up ~24% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~12–19 in this domain), expect 3–5 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)
33questions here
7free pages
3concepts
Questions 31–33
- 31
A company is using a SaaS CRM system. They are using the CSA Cloud Controls Matrix to assess their security responsibilities. The provider is responsible for the application and infrastructure, but the customer must manage their own data. Which control is MOST likely to be the customer's responsibility?
Select an answer first - 32
A company is using a cloud provider's serverless function service. They are mapping security controls to the shared responsibility model. Which of the following controls is the customer responsible for implementing?
Select an answer first - 33
A company is adopting the NIST Cybersecurity Framework and needs to implement controls for the 'Protect' function. They are using a cloud provider's identity and access management (IAM) service. Which control implementation aligns with the 'Protect' function?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GCLD
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCLD” is a trademark of its owner, used for identification only.