
GIAC Cloud Security Automation
Domain 3Objective 3
Runtime Security in Container Orchestration GCSA Practice Questions (Page 6)
Part of the Container Orchestration Architecture and Security domain, which makes up ~19% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–15 in this domain), expect 3–4 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
6concepts
Questions 26–30
- 26
How does Kubernetes admission control integrate with runtime security tools?
Select an answer first - 27
A security analyst is evaluating runtime security tools for a Kubernetes environment. The team needs a tool that can detect anomalous process execution, file system access, and network connections inside containers, and also enforce custom rules. Which tool is best suited for this requirement?
Select an answer first - 28
A security team wants to detect anomalous behavior in their Kubernetes cluster, such as a container spawning a process that is not in the container image's original process tree. They have a SIEM that can receive alerts. Which tool and configuration would best meet this need?
Select an answer first - 29
A company is deploying a new microservices application on Kubernetes. The security team wants to ensure that only approved container images are used and that containers cannot run with elevated privileges. Which combination of controls should they implement?
Select an answer first - 30
A Kubernetes administrator wants to enforce a policy that prevents containers from running as the root user. They also want to ensure that any violation is logged and the pod is not created. Which mechanism should they use?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCSA” is a trademark of its owner, used for identification only.