Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Cloud Security Essentials

Domain 1Objective 2

Understanding Shared Responsibility and Threat Informed Defense GCLD Practice Questions (Page 7)

Part of the Cloud Fundamentals and Shared Responsibility domain, which makes up ~24% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~12–19 in this domain), expect 3–5 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)

37questions here
8free pages
2concepts

Questions 31–35

  1. 31application · medium

    A company is moving a legacy application to an infrastructure-as-a-service (IaaS) environment. The security team is performing a risk assessment and must determine who is responsible for patching the guest operating system of the virtual machines. Which statement accurately reflects the shared responsibility model for IaaS?

    Select an answer first
  2. 32application · medium

    A company is using a serverless compute service (Function-as-a-Service) to run event-driven code. The security team is documenting responsibilities for securing the runtime environment. According to the shared responsibility model, which responsibility remains with the customer?

    Select an answer first
  3. 33expert · hard

    A security team is using threat intelligence to prioritize cloud security investments. The intelligence shows that adversaries are exploiting weak identity and access management (IAM) policies to escalate privileges. The team has a limited budget and must choose between implementing a cloud access security broker (CASB) or conducting a thorough IAM policy review and cleanup. Which choice is more aligned with threat-informed defense?

    Select an answer first
  4. 34expert · hard

    A security team is using threat intelligence to prioritize cloud security investments. The intelligence shows that the most common attack vector is exposed management interfaces with weak passwords. The team has a limited budget and must choose one control. Which control is most aligned with threat-informed defense?

    Select an answer first
  5. 35application · medium

    A security team is reviewing threat intelligence that shows adversaries are using exposed cloud storage keys to access sensitive data. Which control would be most effective in preventing this attack?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCLD” is a trademark of its owner, used for identification only.