
GIAC Cloud Security Essentials
Domain 1Objective 4
Risk Management and Compliance GCLD Practice Questions (Page 5)
Part of the Cloud Fundamentals and Shared Responsibility domain, which makes up ~24% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~12–19 in this domain), expect 3–5 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)
46questions here
10free pages
5concepts
Questions 21–25
- 21
A company is using a cloud provider's serverless compute service to run code that processes sensitive data. The company is subject to GDPR and needs to ensure that data is not stored longer than necessary. Which responsibility does the customer have in this serverless model?
Select an answer first - 22
A hospital is using a cloud-based SaaS application for patient scheduling. The application stores health records. The hospital is subject to HIPAA. What should the hospital obtain from the SaaS provider to support their compliance?
Select an answer first - 23
How do cloud service providers (CSPs) support customer compliance with regulatory frameworks?
Select an answer first - 24
Which compliance framework is specifically designed to protect the privacy of personal data of individuals in the European Union?
Select an answer first - 25
A security team discovers that a cloud storage bucket containing sensitive data is publicly readable. After restricting access, what is the most important next step in the risk management process?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCLD” is a trademark of its owner, used for identification only.