
GIAC Cloud Security Automation
Domain 3Objective 2
Risks, Authentication, and Access-Control of Container Orchestration GCSA Practice Questions (Page 4)
Part of the Container Orchestration Architecture and Security domain, which makes up ~19% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–15 in this domain), expect 3–4 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
5concepts
Questions 16–20
- 16
A company runs a multi-tenant Kubernetes cluster and wants to ensure that a compromised workload in one tenant cannot reach the API server or other tenants' services. They also want to maintain auditability of all API requests. Which set of controls best achieves this?
Select an answer first - 17
Which characteristic of container orchestration platforms introduces a unique security risk that is not typically present in traditional single-host container deployments?
Select an answer first - 18
A security team is reviewing a Kubernetes cluster that runs workloads for multiple business units. Each business unit has its own namespace, and developers have been granted cluster-admin permissions to deploy their applications. The team is concerned about the risk of a compromised workload in one namespace affecting workloads in other namespaces. Which two actions should the team take to reduce the blast radius of a compromised workload while still allowing developers to deploy their applications?
Select an answer first - 19
A security architect is designing authentication for a Kubernetes cluster that will be accessed by both human users and automated CI/CD pipelines. The architect wants to use short-lived credentials for both, but the CI/CD pipelines need to run for up to an hour. Which approach best balances security and operational needs?
Select an answer first - 20
A company is migrating to Kubernetes and wants to authenticate both human users and automated workloads. They require that human users use corporate SSO, while workloads use short-lived credentials. Which authentication strategy should they implement?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCSA” is a trademark of its owner, used for identification only.