
GIAC Cloud Security Automation
Domain 4Objective 1
Container Lifecycle Security GCSA Practice Questions (Page 2)
Part of the Container and Microservices Lifecycle domain, which makes up ~17% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 3–5 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)
46questions here
10free pages
8concepts
Questions 6–10
- 6
Which monitoring approach is most effective for detecting anomalous behavior in a containerized environment?
Select an answer first - 7
Which registry security measure helps ensure that an image has not been tampered with after it was pushed?
Select an answer first - 8
Which Linux security module is commonly used to restrict a container's system calls at the kernel level?
Select an answer first - 9
A development team uses a public container registry to pull base images. The security team wants to reduce the risk of pulling a malicious image that has been tampered with. What should they implement?
Select an answer first - 10
A Kubernetes cluster has a mix of workloads. The security team wants to prevent any workload from accessing the Kubernetes API server except for a specific service account. They also want to ensure that secrets are only accessible to the pods that need them. Which combination of controls should they implement?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCSA” is a trademark of its owner, used for identification only.