Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Cloud Security Automation

Domain 3Objective 2

Risks, Authentication, and Access-Control of Container Orchestration GCSA Practice Questions (Page 8)

Part of the Container Orchestration Architecture and Security domain, which makes up ~19% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–15 in this domain), expect 3–4 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)

38questions here
8free pages
5concepts

Questions 36–38

  1. 36expert · hard

    A company wants to run untrusted third-party workloads in a Kubernetes cluster and wants to minimize the risk of a container breakout affecting the host or other tenants. They also want to maintain the ability to schedule workloads efficiently. Which approach best balances security and efficiency?

    Select an answer first
  2. 37application · medium

    A Kubernetes cluster is configured to use a service account for a background job that needs to list pods in its namespace. The job runs for a few minutes and then terminates. The security team wants to minimize the risk of the service account token being stolen and used later. Which approach should they take?

    Select an answer first
  3. 38expert · hard

    A security engineer is designing a multi-tenant Kubernetes cluster where each tenant has a namespace. The engineer wants to ensure that a tenant cannot exhaust the cluster's resources and affect other tenants. Which combination of controls should they implement?

    Select an answer first
Finished these 3 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to GCSA

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCSA” is a trademark of its owner, used for identification only.