
GIAC Cloud Security Automation
Domain 4Objective 1
Container Lifecycle Security GCSA Practice Questions (Page 7)
Part of the Container and Microservices Lifecycle domain, which makes up ~17% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 3–5 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)
46questions here
10free pages
8concepts
Questions 31–35
- 31
A security operations team wants to detect anomalous behavior in a containerized application, such as unexpected network connections or attempts to write to sensitive host paths. The team already collects container logs and metrics. Which additional control should be implemented to meet this goal?
Select an answer first - 32
What does 'image provenance' refer to in container supply chain security?
Select an answer first - 33
What is the primary purpose of auditing container environments?
Select an answer first - 34
Which Kubernetes feature is specifically designed to store sensitive data such as passwords and API keys?
Select an answer first - 35
A company's CI/CD pipeline builds container images from source code and pushes them to a private registry. The security team wants to ensure that the images are built from trusted source code and that the build process itself is not tampered with. Which control should be added to the pipeline?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCSA” is a trademark of its owner, used for identification only.