
GIAC Cloud Security Automation
Domain 1Objective 2
Securing the DevOps Workflow GCSA Practice Questions (Page 1)
Part of the DevOps and Cloud Infrastructure domain, which makes up ~24% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~12–19 in this domain), expect 3–5 from this objective — we provide 52 practice questions to prepare you well beyond it. (estimate)
52questions here
11free pages
10concepts
Questions 1–5
- 1
Which of the following is an example of using policy-as-code to enforce compliance?
Select an answer first - 2
A financial services company must comply with a regulation that requires all storage buckets to be encrypted and access to be logged. They use a CI/CD pipeline to deploy infrastructure. How should they enforce this policy?
Select an answer first - 3
A development team uses a CI/CD pipeline that builds a container image, runs unit tests, and deploys to a staging environment. The security team wants to automatically block deployment if the image contains a critical vulnerability. The pipeline already has access to a container registry and a secrets vault. Which approach should the security team implement?
Select an answer first - 4
A company uses a CI/CD pipeline to build and deploy a containerized application. They want to ensure that the container image used in production is exactly the same as the one that was tested and approved. Which practice should they implement?
Select an answer first - 5
What is the purpose of signing container images?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCSA” is a trademark of its owner, used for identification only.