
GIAC Cloud Security Automation
Domain 5Objective 1
Edge Identity and Authentication GCSA Practice Questions (Page 5)
Part of the Identity, Secrets, and Supply Chain domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 3–5 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)
48questions here
10free pages
6concepts
Questions 21–25
- 21
A company manages a fleet of edge devices that need to access a cloud API using API keys. The keys are currently stored in a configuration file on each device. The security team wants to reduce the risk of key exposure and implement automatic rotation. Which approach is the most secure and operationally efficient?
Select an answer first - 22
A multinational corporation has offices in several countries, each with its own Active Directory forest. Employees travel between offices and need to access edge applications in each location without repeated logins. The security team wants to use identity federation to enable single sign-on across these forests. Which technology should they implement?
Select an answer first - 23
A manufacturing company operates edge gateways in multiple plants. Each plant uses a different identity provider (IdP) for its local operators. The company wants operators to sign in once at any plant and have their permissions enforced by the edge gateways based on group membership from their home IdP. The gateways are in a separate network domain from the corporate IdPs. Which solution should the security architect choose?
Select an answer first - 24
A financial services firm uses edge devices that authenticate to a central API using OAuth 2.0 tokens obtained from an identity provider. The firm wants to implement zero trust by continuously verifying the device's security posture before granting access to sensitive data. Which approach best achieves this while minimizing latency for legitimate requests?
Select an answer first - 25
A security architect is designing access for edge devices that use federated identities. The architect wants to enforce zero trust by limiting each device's access to only the APIs it needs. Which strategy best achieves this?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCSA” is a trademark of its owner, used for identification only.