
GIAC Cloud Security Essentials
Domain 3Objective 2
Secrets Management GCLD Practice Questions (Page 1)
Part of the Identity, Access, and Secrets domain, which makes up ~15% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 4–6 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)
51questions here
11free pages
10concepts
Questions 1–5
- 1
Which of the following is a standard method to protect secrets in transit between an application and a secrets management service?
Select an answer first - 2
A company suspects that a database password stored in a secrets manager has been compromised. The password is used by multiple applications, some of which cache the password for long periods. The security team needs to rotate the password and ensure that all applications eventually use the new password without manual intervention. What is the best approach?
Select an answer first - 3
A company is decommissioning a legacy application that uses a shared service account to access a secrets manager. The security team wants to ensure that the service account cannot be used after the application is retired. What is the BEST way to accomplish this?
Select an answer first - 4
What is a primary benefit of using a centralized secrets management service instead of storing secrets in application configuration files?
Select an answer first - 5
A security team needs to detect when a service account is retrieving secrets from Azure Key Vault at unusual times or from unexpected IP addresses. They also want to be alerted if a secret is deleted. What should they enable?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCLD” is a trademark of its owner, used for identification only.