
GIAC Cloud Security Automation
Domain 3Objective 2
Risks, Authentication, and Access-Control of Container Orchestration GCSA Practice Questions (Page 5)
Part of the Container Orchestration Architecture and Security domain, which makes up ~19% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–15 in this domain), expect 3–4 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
5concepts
Questions 21–25
- 21
A company operates a Kubernetes cluster with a shared control plane but wants to give each business unit the ability to manage its own namespaces without granting cluster-admin. They also need to prevent a compromised workload from accessing the host network. Which approach best meets these needs?
Select an answer first - 22
In Kubernetes RBAC, which object defines a set of permissions (verbs and resources) that can be granted to a user or service account?
Select an answer first - 23
A company runs a multi-tenant Kubernetes cluster where development teams deploy workloads into shared namespaces. The security team wants to reduce the risk of one tenant's workload interfering with another's network traffic. Which control should they implement?
Select an answer first - 24
A company wants to isolate development and production workloads in the same Kubernetes cluster to reduce the risk of accidental interference. Which control should be implemented?
Select an answer first - 25
Which component of a container orchestration platform is most commonly exposed as a network API and therefore represents a significant attack surface?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCSA” is a trademark of its owner, used for identification only.