
GIAC Cloud Security Automation
Domain 2Objective 1
Automated Cloud Remediation GCSA Practice Questions (Page 9)
Part of the Cloud Security Automation and Compliance domain, which makes up ~17% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 3–5 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)
49questions here
10free pages
9concepts
Questions 41–45
- 41
A security engineer is configuring automated remediation for a public cloud environment. The team wants to automatically revoke overly permissive security group rules as soon as they are created. The engineer has a Cloud Security Posture Management (CSPM) tool that can emit a real-time event when a new security group rule is detected. Which approach best meets the requirement?
Select an answer first - 42
A security team has implemented automated remediation for several security findings. The compliance team needs to provide evidence that remediation actions are working. What should the team implement to meet this requirement?
Select an answer first - 43
A security team has implemented automated remediation for a set of security findings. The compliance team wants to provide auditors with a report that shows the number of findings, the remediation actions taken, and the success rate. Which reporting approach should the team use?
Select an answer first - 44
A company uses Terraform with OPA policies to enforce security standards. The security team wants to automatically remediate any drift from the policy baseline. However, the team is concerned that automatic remediation could override manual changes made by developers for legitimate reasons. Which approach best balances policy enforcement with developer flexibility?
Select an answer first - 45
A company uses HashiCorp Sentinel to enforce policies on Terraform plans. The security team wants to automatically remediate any infrastructure that is deployed without the required encryption settings. The team uses a GitOps workflow where all changes are merged to a main branch. Which approach should they take to enforce the policy and remediate non-compliant resources?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCSA” is a trademark of its owner, used for identification only.