
GIAC Cloud Security Essentials
Domain 2Objective 2
Securing Cloud Networks GCLD Practice Questions (Page 3)
Part of the Cloud Networking and Security domain, which makes up ~16% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–13 in this domain), expect 3–4 from this objective — we provide 29 practice questions to prepare you well beyond it. (estimate)
29questions here
6free pages
7concepts
Questions 11–15
- 11
Which statement correctly describes the difference between security groups and network ACLs?
Select an answer first - 12
A system administrator needs to securely manage a Linux instance located in a private subnet of a cloud VPC. The company's security policy requires that administrative access be logged and that the administrator's identity be authenticated using the corporate identity provider. Which solution should the administrator use?
Select an answer first - 13
Which technology creates an encrypted tunnel over the public internet to securely connect a remote user to a cloud virtual network?
Select an answer first - 14
A security analyst notices that a web server in a public subnet is receiving inbound traffic on port 22 (SSH) from a wide range of IP addresses, even though the security group only allows SSH from the corporate VPN CIDR. The analyst suspects the traffic is being blocked by the security group but wants to verify. Which action should the analyst take to confirm whether the security group is actually blocking the traffic?
Select an answer first - 15
What is the primary purpose of VPC flow logs?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCLD” is a trademark of its owner, used for identification only.