
GIAC Cloud Security Automation
Domain 3Objective 2
Risks, Authentication, and Access-Control of Container Orchestration GCSA Practice Questions (Page 7)
Part of the Container Orchestration Architecture and Security domain, which makes up ~19% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–15 in this domain), expect 3–4 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
5concepts
Questions 31–35
- 31
A company wants to ensure that all requests to the Kubernetes API server are authenticated and that sensitive actions are recorded for audit. Which combination of controls should be implemented?
Select an answer first - 32
A security team wants to enforce that no workload in a cluster can run as root or mount the host filesystem. They also want to ensure that only approved images are used. Which combination of admission controls should they implement?
Select an answer first - 33
An organization is deploying a production Kubernetes cluster and wants to ensure that only authenticated and authorized users can access the API server. They also need to maintain an audit trail of all API requests for compliance. Which combination of controls should they implement?
Select an answer first - 34
Which Kubernetes resource is used to control network traffic between pods and services, enabling micro-segmentation?
Select an answer first - 35
A Kubernetes cluster is configured with RBAC and uses OIDC for user authentication. A security audit reveals that a former employee's OIDC account is still active and has cluster-admin privileges. The company wants to ensure that this account cannot be used to access the cluster. What is the most effective immediate action?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCSA” is a trademark of its owner, used for identification only.