Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Cloud Security Essentials

Domain 1Objective 2

Understanding Shared Responsibility and Threat Informed Defense GCLD Practice Questions (Page 4)

Part of the Cloud Fundamentals and Shared Responsibility domain, which makes up ~24% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~12–19 in this domain), expect 3–5 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)

37questions here
8free pages
2concepts

Questions 16–20

  1. 16application · medium

    A company is using a cloud provider's platform-as-a-service (PaaS) offering to host a web application. The provider manages the runtime environment and the operating system. Which security task is still the customer's responsibility?

    Select an answer first
  2. 17application · medium

    A security operations center is using the MITRE ATT&CK framework to map observed adversary behavior. They notice that an attacker is using a legitimate cloud management API to create a new virtual machine for cryptocurrency mining. Which ATT&CK tactic does this behavior primarily represent?

    Select an answer first
  3. 18expert · hard

    A company is using a hybrid cloud environment with both on-premises and cloud resources. The security team is defining responsibilities for a new application that uses an IaaS virtual machine in the cloud and an on-premises database. Which party is responsible for patching the guest OS of the cloud VM?

    Select an answer first
  4. 19expert · hard

    A security team is using threat intelligence to improve their cloud security posture. The intelligence indicates that adversaries are using a technique called 'living off the land' by abusing legitimate cloud management tools to perform malicious actions. Which control would be most effective in detecting this behavior?

    Select an answer first
  5. 20application · medium

    A threat intelligence report indicates that adversaries are using phishing emails to obtain cloud console credentials and then modifying multi-factor authentication settings to lock out legitimate users. Which control would be most effective in mitigating this attack chain?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCLD” is a trademark of its owner, used for identification only.