
GIAC Cloud Security Automation
Domain 5Objective 1
Edge Identity and Authentication GCSA Practice Questions (Page 9)
Part of the Identity, Secrets, and Supply Chain domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 3–5 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)
48questions here
10free pages
6concepts
Questions 41–45
- 41
A company has edge devices that authenticate using certificates. They want to implement zero trust, but they also need to minimize the performance impact on the devices. Which approach balances security and performance?
Select an answer first - 42
A company builds edge devices that include third-party software components. The security team wants to ensure that these components are authentic and have not been tampered with before they are integrated into the device image. Which control should they implement in their CI/CD pipeline?
Select an answer first - 43
A retail chain deploys point-of-sale (POS) terminals at hundreds of stores. Each terminal runs a containerized payment application that must authenticate to a central cloud backend. The network team prohibits inbound connections from the internet to the stores, and the terminals have no stable public IP addresses. The security team requires that each terminal prove its identity cryptographically before any API call is accepted. Which approach should the platform team implement?
Select an answer first - 44
A company has edge devices that use mutual TLS to authenticate to a cloud backend. They want to implement zero trust by continuously verifying the device's identity and posture. Which additional control is most aligned?
Select an answer first - 45
A utility company manages thousands of smart meters that communicate with a central system. Each meter has a unique identity and uses certificates for authentication. The security team wants to ensure that a compromised meter cannot be used to access other meters' data. Which principle should guide their design?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCSA” is a trademark of its owner, used for identification only.