
GIAC Cloud Security Automation
Domain 2Objective 2
Cloud Compliance as Code GCSA Practice Questions (Page 5)
Part of the Cloud Security Automation and Compliance domain, which makes up ~17% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 3–5 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
10concepts
Questions 21–25
- 21
A DevOps team is adopting Terraform to manage AWS infrastructure. They want to prevent deployment of S3 buckets that allow public read access. Which approach should they implement to catch this violation before any resource is created?
Select an answer first - 22
At which stage of a CI/CD pipeline can compliance checks be applied?
Select an answer first - 23
When a compliance test fails, what is the typical next step in an automated pipeline?
Select an answer first - 24
A security team is responsible for managing compliance policies as code in a Git repository. They need to ensure that all changes are traceable and that there is a clear audit trail. They are considering using Git tags to mark policy versions and a CI/CD pipeline to test policies. What is the most important practice to ensure traceability and a clear audit trail?
Select an answer first - 25
A company is migrating to Google Cloud and needs to continuously assess their resources against the CIS Google Cloud Computing Platform Benchmark. They want to use a native GCP service to automate this assessment and generate a compliance report. What should they use?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCSA” is a trademark of its owner, used for identification only.