
GIAC Cloud Security Essentials
Domain 1Objective 2
Understanding Shared Responsibility and Threat Informed Defense GCLD Practice Questions (Page 2)
Part of the Cloud Fundamentals and Shared Responsibility domain, which makes up ~24% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~12–19 in this domain), expect 3–5 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
2concepts
Questions 6–10
- 6
A company is using a cloud provider's managed Kubernetes service. The security team is determining who is responsible for securing the worker nodes' operating system. According to the shared responsibility model, who is responsible?
Select an answer first - 7
A company is migrating a critical application to the cloud and must choose between IaaS and PaaS. The security team is concerned about the effort required to patch the operating system and middleware. The compliance team requires the ability to install a custom security agent on the host. Which service model best balances these requirements?
Select an answer first - 8
A company is using a cloud provider's SaaS collaboration platform. The security team is concerned about data leakage through external sharing. The provider offers a data loss prevention (DLP) feature, but it requires additional configuration. The team has limited resources and must decide whether to configure the DLP feature or rely on user training. Which approach is more effective in reducing data leakage risk?
Select an answer first - 9
A company is using a cloud provider's IaaS to host a web server. The provider offers a managed web application firewall (WAF) that can be deployed in front of the server. The security team wants to reduce the risk of web application attacks but is concerned about the cost and management overhead. Which approach best balances security and cost?
Select an answer first - 10
A security team is using threat intelligence to design a detection strategy. The intelligence indicates that an adversary group uses cloud API calls to enumerate resources and identify misconfigurations. Which control is most directly informed by this threat pattern?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCLD” is a trademark of its owner, used for identification only.