Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Cloud Security Automation

Domain 3Objective 2

Risks, Authentication, and Access-Control of Container Orchestration GCSA Practice Questions (Page 2)

Part of the Container Orchestration Architecture and Security domain, which makes up ~19% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–15 in this domain), expect 3–4 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)

38questions here
8free pages
5concepts

Questions 6–10

  1. 6application · medium

    A security analyst is assessing the risks of a Kubernetes cluster that hosts multiple customer applications. The cluster uses a shared control plane, and each customer's workloads run in separate namespaces. The analyst is particularly concerned about the risk of a compromised pod being used to attack the Kubernetes API server. Which control is most directly effective at mitigating this specific risk?

    Select an answer first
  2. 7application · medium

    An organization wants to allow employees to authenticate to the Kubernetes API server using their existing corporate single sign-on (SSO) credentials. Which authentication mechanism should be configured?

    Select an answer first
  3. 8foundation · easy

    Which practice is most effective for protecting the Kubernetes API server from unauthorized network access?

    Select an answer first
  4. 9foundation · easy

    Which authentication method is commonly used by a human administrator to interact with a Kubernetes cluster via kubectl?

    Select an answer first
  5. 10expert · hard

    A large enterprise runs a multi-tenant Kubernetes cluster with a shared control plane. Each tenant has a namespace, and the security team is concerned about the risk of a tenant's workload using a vulnerability in the kubelet to access other tenants' pods. They are evaluating controls to mitigate this risk. Which control is most effective at preventing a compromised workload from exploiting the kubelet to reach other tenants' pods?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCSA” is a trademark of its owner, used for identification only.