
GIAC Cloud Security Automation
Domain 5Objective 2
Managing Secrets GCSA Practice Questions (Page 5)
Part of the Identity, Secrets, and Supply Chain domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 3–5 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
7concepts
Questions 21–25
- 21
What is a primary risk of hardcoding secrets in application source code?
Select an answer first - 22
A company is comparing cloud-native secret storage with a third-party vault. They require automatic rotation, fine-grained access control, and integration with their cloud IAM. Which solution best meets these requirements?
Select an answer first - 23
An application needs to retrieve a secret at runtime, but the team wants to avoid exposing the secret in environment variables or logs. What is the best method for secret injection?
Select an answer first - 24
A security team wants to detect if a compromised application is exfiltrating secrets by making unusual vault API calls. What should they enable?
Select an answer first - 25
What is the primary goal of auditing secret usage?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCSA” is a trademark of its owner, used for identification only.