Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Cloud Security Automation

Domain 5Objective 2

Managing Secrets GCSA Practice Questions (Page 6)

Part of the Identity, Secrets, and Supply Chain domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 3–5 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)

44questions here
9free pages
7concepts

Questions 26–30

  1. 26application · medium

    A CI/CD pipeline needs to deploy an application that requires a database password. The team wants to ensure that the password is not visible in the pipeline logs and is rotated automatically. What is the best practice?

    Select an answer first
  2. 27application · medium

    A startup stores database credentials in a plaintext configuration file that is committed to a private Git repository. After a security review, they want to move to a managed secret store. The team also needs to know which developers accessed the credentials and when. Which combination of actions should they take?

    Select an answer first
  3. 28expert · hard

    A security analyst is investigating a potential secret leak. They see that a service account has accessed a secret outside of its normal pattern. The analyst needs to determine if the access was legitimate. What is the most effective way to correlate the access with a specific workload?

    Select an answer first
  4. 29expert · hard

    A team is implementing automated rotation for a database password. The application uses a connection pool and does not handle connection failures gracefully. The team wants to minimize downtime during rotation. What is the best strategy?

    Select an answer first
  5. 30application · medium

    A company uses AWS Secrets Manager to store API keys for multiple microservices. Each microservice runs on an EC2 instance with an IAM role. The security team wants to ensure that each microservice can only access its own secrets and that access is logged. What should they configure?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCSA” is a trademark of its owner, used for identification only.