Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Cloud Security Essentials

Domain 3Objective 2

Secrets Management GCLD Practice Questions (Page 9)

Part of the Identity, Access, and Secrets domain, which makes up ~15% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 4–6 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)

51questions here
11free pages
10concepts

Questions 41–45

  1. 41foundation · easy

    Which stage of the secret lifecycle involves permanently removing a secret from the system?

    Select an answer first
  2. 42foundation · easy

    Why is automated secret rotation considered a best practice?

    Select an answer first
  3. 43foundation · easy

    What is a recommended way to provide secrets to a CI/CD pipeline during a build?

    Select an answer first
  4. 44application · medium

    A company currently stores database credentials in a plaintext configuration file on each application server. They want to move to a centralized secrets management solution to improve security and simplify rotation. What is the first step they should take?

    Select an answer first
  5. 45expert · hard

    A company uses a centralized secrets manager (e.g., AWS Secrets Manager) for all application secrets. They have multiple AWS accounts: production, staging, and development. They want to allow applications in each account to retrieve only the secrets that belong to their environment, and they want to avoid duplicating secrets across accounts. What is the most secure and maintainable approach?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCLD” is a trademark of its owner, used for identification only.