
GIAC Cloud Security Automation
Domain 2Objective 3
Policy Enforcement GCSA Practice Questions (Page 3)
Part of the Cloud Security Automation and Compliance domain, which makes up ~17% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 3–5 from this objective — we provide 41 practice questions to prepare you well beyond it. (estimate)
41questions here
9free pages
6concepts
Questions 11–15
- 11
What does 'policy drift' refer to in cloud security automation?
Select an answer first - 12
A security team needs to automate auditing of their AWS environment against the NIST 800-53 framework. They want to generate compliance reports and receive alerts when resources fall out of compliance. Which AWS service should they use?
Select an answer first - 13
Which cloud service is commonly used as a policy enforcement point for applying compliance policies to Azure resources?
Select an answer first - 14
Which statement best describes the core benefit of implementing security policies as code?
Select an answer first - 15
A company uses AWS Organizations and wants to enforce a policy that prevents the creation of EC2 instances without a specific tag. They want the policy to apply to all accounts in the organization, including future accounts. Which enforcement point should they use?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCSA” is a trademark of its owner, used for identification only.