
GIAC Cloud Security Automation
Domain 2Objective 2
Cloud Compliance as Code GCSA Practice Questions (Page 3)
Part of the Cloud Security Automation and Compliance domain, which makes up ~17% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 3–5 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
10concepts
Questions 11–15
- 11
What is a key advantage of using a policy-as-code framework over traditional manual compliance checks?
Select an answer first - 12
A company uses Azure Policy to enforce tagging standards on all resources. They have a requirement that any resource created without the required 'CostCenter' tag must be automatically corrected within 15 minutes. The team wants to use a native Azure service to handle this without writing custom code. What should they configure?
Select an answer first - 13
A compliance officer needs a monthly, exportable report that shows the compliance status of all AWS resources against the CIS AWS Foundations Benchmark. Which AWS service should be used to generate this report?
Select an answer first - 14
A development team uses GitHub Actions to deploy Kubernetes manifests to a cluster. They want to enforce that all container images come from an approved registry before the manifests are applied. Which step should they add to the workflow?
Select an answer first - 15
A security engineer needs to validate that a set of AWS resources meets the company's encryption standards. They want to run automated tests that produce a pass/fail result and store the results for audit. Which approach should they use?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCSA” is a trademark of its owner, used for identification only.