
GIAC Cloud Security Automation
Domain 3Objective 3
Runtime Security in Container Orchestration GCSA Practice Questions (Page 7)
Part of the Container Orchestration Architecture and Security domain, which makes up ~19% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–15 in this domain), expect 3–4 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
6concepts
Questions 31–35
- 31
A security team is integrating runtime security with a Kubernetes cluster that uses a service mesh. They want to enforce a policy that blocks a specific container from making outbound connections to a known malicious IP address. The policy should be applied at the network layer and should not require changes to the container image. Which approach should they use?
Select an answer first - 32
What is the primary purpose of monitoring container activity for anomalies in an orchestration platform?
Select an answer first - 33
Which Kubernetes native mechanism can be used to enforce runtime security policies that restrict container capabilities?
Select an answer first - 34
A security team wants to implement runtime security for containers running in a Kubernetes cluster. They need a tool that can enforce policies based on container behavior, such as blocking the execution of certain binaries and preventing writes to sensitive directories. Which tool should they choose?
Select an answer first - 35
A security analyst wants to detect if a container is attempting to mount the host's Docker socket, which could allow the container to control the host's Docker daemon. Which tool and configuration would best detect this?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCSA” is a trademark of its owner, used for identification only.