
GIAC Cloud Security Automation
Domain 1Objective 3
Deploying Cloud Infrastructure as Code GCSA Practice Questions (Page 7)
Part of the DevOps and Cloud Infrastructure domain, which makes up ~24% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~12–19 in this domain), expect 3–5 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
10concepts
Questions 31–35
- 31
A company uses Terraform to manage its infrastructure. The security team needs to audit who made changes to the infrastructure and when. They also need to be able to trace a specific change back to the code that caused it. What should they implement?
Select an answer first - 32
Which of the following is a trade-off of using imperative Infrastructure as Code?
Select an answer first - 33
An administrator notices that a security group in AWS was manually modified, and the Terraform state no longer matches the actual infrastructure. They want to restore the desired configuration. What is the appropriate action?
Select an answer first - 34
A company uses Terraform to manage its infrastructure. They have a policy that all changes must go through the CI/CD pipeline. However, a developer manually changed a resource in the cloud console to fix an urgent issue. The next `terraform plan` will detect this drift and revert the change. The team wants to keep the manual change but also maintain the IaC as the source of truth. What is the best way to handle this?
Select an answer first - 35
How can compliance checks be integrated into Infrastructure as Code deployments?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCSA” is a trademark of its owner, used for identification only.