
GIAC Cloud Security Automation
Domain 3Objective 3
Runtime Security in Container Orchestration GCSA Practice Questions (Page 2)
Part of the Container Orchestration Architecture and Security domain, which makes up ~19% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–15 in this domain), expect 3–4 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
6concepts
Questions 6–10
- 6
A company wants to implement runtime security for its Kubernetes cluster using an open-source tool. They need to detect and alert on suspicious system calls, such as attempts to write to /etc/passwd. Which tool should they choose?
Select an answer first - 7
What is the primary function of Falco in a container orchestration environment?
Select an answer first - 8
A DevOps team runs a Kubernetes cluster with multiple namespaces. They need to detect a potential crypto-mining attack that involves unusual outbound network connections from pods to known mining pools. They already have Prometheus and Grafana for metrics. Which additional tool or configuration would best provide the required detection capability?
Select an answer first - 9
A security team wants to ensure that no container in their Kubernetes cluster runs with the 'privileged' flag. They have a policy-as-code tool that can integrate with Kubernetes. Which integration point should they use to enforce this policy?
Select an answer first - 10
A DevOps team uses Kubernetes with a policy engine to enforce runtime security. They want to prevent any container from running with the `--privileged` flag, and they also want to block the use of host network namespaces. Which Kubernetes-native mechanism should they use to enforce these restrictions at runtime?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCSA” is a trademark of its owner, used for identification only.