Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Cloud Security Automation

Domain 3Objective 3

Runtime Security in Container Orchestration GCSA Practice Questions (Page 5)

Part of the Container Orchestration Architecture and Security domain, which makes up ~19% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–15 in this domain), expect 3–4 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)

37questions here
8free pages
6concepts

Questions 21–25

  1. 21expert · hard

    During a security incident, a container in a Kubernetes pod is executing a reverse shell to an external IP. The incident response team needs to stop the malicious activity while preserving evidence for forensic analysis. The pod is running a stateless application. Which response action should they take?

    Select an answer first
  2. 22expert · hard

    A security team is investigating a potential runtime threat in a Kubernetes cluster. They observe that a container is repeatedly attempting to access the Kubernetes API server from within the pod. The team wants to determine if this is malicious behavior or a legitimate application function. Which approach would provide the most useful information?

    Select an answer first
  3. 23expert · hard

    A security incident has been contained in a Kubernetes cluster. The compromised pod has been isolated, and the attacker's access has been revoked. The incident response team now needs to eradicate the threat and recover the cluster to a known good state. Which action should they take?

    Select an answer first
  4. 24expert · hard

    A Kubernetes cluster runs a mix of trusted internal workloads and untrusted customer-facing workloads. The security team wants to enforce a runtime policy that blocks untrusted workloads from using 'exec' to enter a running container, but they do not want to affect trusted workloads. Which approach is the most effective?

    Select an answer first
  5. 25expert · hard

    A security team wants to enforce a policy that prevents any container from running with the 'hostPID' namespace, which could allow a container to see processes on the host. They also want to detect any attempt to use 'hostPID' at runtime. Which combination of controls should they implement?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCSA” is a trademark of its owner, used for identification only.