Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Cloud Security Automation

Domain 5Objective 2

Managing Secrets GCSA Practice Questions (Page 4)

Part of the Identity, Secrets, and Supply Chain domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 3–5 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)

44questions here
9free pages
7concepts

Questions 16–20

  1. 16foundation · easy

    Which authentication mechanism is commonly used to allow a cloud workload to securely retrieve secrets without storing long-term credentials?

    Select an answer first
  2. 17expert · hard

    A large enterprise uses a central secret management platform (e.g., HashiCorp Vault) to manage secrets for multiple teams. Each team has its own namespace and applications. The security team wants to enforce that applications can only read secrets from their own namespace and that all access is logged. They also want to minimize the number of authentication credentials to manage. Which approach should they take?

    Select an answer first
  3. 18foundation · easy

    Why should secrets never be written to application logs?

    Select an answer first
  4. 19foundation · easy

    What is a recommended method to inject secrets into a containerized application at runtime?

    Select an answer first
  5. 20application · medium

    A company uses a central secrets vault. Each microservice needs to read only its own database credentials. The security team wants to ensure that a compromised service cannot access other services' secrets and that all access is logged. What is the most appropriate configuration?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCSA” is a trademark of its owner, used for identification only.