Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Cloud Penetration Tester

Domain 5Objective 1

Cloud Native Applications and CI/CD Pipelines GCPN Practice Questions (Page 11)

Part of the Application and CI/CD Security domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 5–7 from this objective — we provide 54 practice questions to prepare you well beyond it. (estimate)

54questions here
11free pages
9concepts

Questions 51–54

  1. 51expert · hard

    A software vendor distributes a containerized application to customers. The vendor wants to ensure that customers can verify the authenticity and integrity of the images. The vendor also wants to protect against a compromised build environment. Which approach should be used?

    Select an answer first
  2. 52application · medium

    A cloud team is implementing a CI/CD pipeline for infrastructure changes. The team wants to ensure that only authorized personnel can deploy changes and that all changes are recorded. Which configuration should be used?

    Select an answer first
  3. 53foundation · easy

    Which method is considered secure for storing secrets used in a CI/CD pipeline?

    Select an answer first
  4. 54foundation · easy

    What is the purpose of integrating container security scanning into a CI/CD pipeline?

    Select an answer first
Finished these 4 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to GCPN

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCPN” is a trademark of its owner, used for identification only.