
GIAC Cloud Security Automation
Domain 2Objective 3
Policy Enforcement GCSA Practice Questions (Page 2)
Part of the Cloud Security Automation and Compliance domain, which makes up ~17% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 3–5 from this objective — we provide 41 practice questions to prepare you well beyond it. (estimate)
41questions here
9free pages
6concepts
Questions 6–10
- 6
A company uses Kubernetes and wants to enforce a policy that containers must run as non-root. They want to prevent non-compliant pods from being created. Which enforcement point should they configure?
Select an answer first - 7
In a cloud environment, which component is an example of a policy enforcement point?
Select an answer first - 8
A cloud security team manages infrastructure using Terraform. They need to enforce a policy that all S3 buckets must have versioning enabled. The team wants to catch violations before resources are deployed, and also wants to prevent developers from bypassing the check by running Terraform locally. Which approach should they use?
Select an answer first - 9
What is the purpose of mapping organizational policies to compliance frameworks like CIS or NIST?
Select an answer first - 10
An organization uses AWS Organizations and wants to enforce a policy that prevents any IAM user from creating access keys in any account. They have a policy-as-code repository where all policies are version-controlled and reviewed. Which enforcement point should they configure to achieve this?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCSA” is a trademark of its owner, used for identification only.