
GIAC Cloud Security Essentials
Domain 5Objective 2
Using Sensitive Data GCLD Practice Questions (Page 1)
Part of the Data Protection and Automation domain, which makes up ~23% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~12–18 in this domain), expect 4–6 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)
53questions here
11free pages
10concepts
Questions 1–5
- 1
A large enterprise uses a cloud collaboration platform where employees share files. The security team wants to prevent credit card numbers from being shared externally while allowing internal sharing. They also need to know if any files containing credit card numbers have already been shared externally. Which approach best meets both requirements?
Select an answer first - 2
A cloud environment hosts a database containing PHI. The security team wants to ensure that only healthcare providers with a specific role can access the data, and that all access is logged for auditing. Which combination of controls should be implemented?
Select an answer first - 3
What is the primary goal of a Data Loss Prevention (DLP) policy in a cloud environment?
Select an answer first - 4
A company is implementing a DLP solution to protect sensitive data in a cloud email service. The security team wants to prevent sensitive data from being sent to external recipients while allowing internal sharing. They also need to ensure that any blocked attempts are logged for compliance. Which configuration should be used?
Select an answer first - 5
A cloud security team needs to detect unauthorized access to a database containing financial records. They want to know who accessed the data, when, and from which IP address. Which control should be prioritized?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCLD” is a trademark of its owner, used for identification only.