
GIAC Cloud Security Essentials
Domain 5Objective 2
Using Sensitive Data GCLD Practice Questions (Page 8)
Part of the Data Protection and Automation domain, which makes up ~23% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~12–18 in this domain), expect 4–6 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)
53questions here
11free pages
10concepts
Questions 36–40
- 36
A cloud migration team is moving application data to object storage. They need to identify which objects contain personally identifiable information (PII) so they can apply stricter controls. What is the most effective way to identify PII in the objects?
Select an answer first - 37
A software development team needs realistic customer data to test a new feature, but the production database contains PII. The security policy prohibits using real PII in non-production environments. Which technique should the team use to create test data that remains useful for development?
Select an answer first - 38
A company is implementing access controls for a cloud storage bucket that contains data classified as 'Confidential'. The compliance team requires that access be granted based on the principle of least privilege, but the company also needs to allow temporary access for external auditors. What is the best way to manage this?
Select an answer first - 39
What is the primary purpose of auditing access to sensitive data in a cloud environment?
Select an answer first - 40
Which tool is commonly used to discover sensitive data stored in cloud object storage services like Amazon S3?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCLD” is a trademark of its owner, used for identification only.