Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Cloud Security Essentials

Domain 3Objective 2

Secrets Management GCLD Practice Questions (Page 7)

Part of the Identity, Access, and Secrets domain, which makes up ~15% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 4–6 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)

51questions here
11free pages
10concepts

Questions 31–35

  1. 31foundation · easy

    Which of the following is an example of monitoring secret usage to detect potential compromise?

    Select an answer first
  2. 32foundation · easy

    How should a cloud application retrieve a database password from a secrets management service?

    Select an answer first
  3. 33foundation · easy

    What is the purpose of fine-grained access control for secrets?

    Select an answer first
  4. 34expert · hard

    A company is migrating from storing secrets in environment variables to a centralized secrets manager. They have hundreds of applications, each with different secrets. The security team wants to minimize the risk of secrets being exposed during the migration. What is the BEST migration strategy?

    Select an answer first
  5. 35expert · hard

    A company uses Jenkins for CI/CD. They need to deploy to multiple cloud environments (dev, staging, prod) and want to ensure that production credentials are not accessible to developers or to jobs running for non-production branches. They also want to avoid storing credentials in Jenkins' global configuration. What is the best approach?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCLD” is a trademark of its owner, used for identification only.