
GIAC Cloud Security Essentials
Domain 5Objective 2
Using Sensitive Data GCLD Practice Questions (Page 3)
Part of the Data Protection and Automation domain, which makes up ~23% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~12–18 in this domain), expect 4–6 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)
53questions here
11free pages
10concepts
Questions 11–15
- 11
Which encryption method protects data while it is being transmitted between a user's browser and a cloud application?
Select an answer first - 12
What is the principle of least privilege in the context of access control for sensitive data?
Select an answer first - 13
A hospital is moving patient health records to a cloud storage service. The compliance officer requires that all PHI be protected both while stored and while transmitted between the hospital and the cloud. Which combination of controls should be implemented?
Select an answer first - 14
A company stores sensitive financial data in a cloud database. The security team wants to ensure that even if the underlying storage is compromised, the data remains unreadable. They also want to control which applications can access the decryption keys. Which approach should they take?
Select an answer first - 15
What is the primary purpose of creating a data inventory and mapping for sensitive data in the cloud?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCLD” is a trademark of its owner, used for identification only.