
GIAC Cloud Security Automation
Domain 1Objective 2
Securing the DevOps Workflow GCSA Practice Questions (Page 10)
Part of the DevOps and Cloud Infrastructure domain, which makes up ~24% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~12–19 in this domain), expect 3–5 from this objective — we provide 52 practice questions to prepare you well beyond it. (estimate)
52questions here
11free pages
10concepts
Questions 46–50
- 46
A DevOps team wants to detect and respond to security incidents in their cloud environment. They have a CI/CD pipeline that deploys applications. Which practice should they implement to ensure they can quickly identify and respond to incidents?
Select an answer first - 47
An infrastructure team uses Terraform to manage cloud resources. They want to ensure that no resource is created with a public IP address unless explicitly allowed. Which approach should they implement in their CI/CD pipeline?
Select an answer first - 48
A software company distributes a binary application. The security team wants to ensure that customers can verify that the binary was built from the exact source code that the company published. The company uses a CI/CD pipeline to build the binary. Which approach provides the strongest supply chain assurance?
Select an answer first - 49
A company uses a private container registry to store images for production. The security team wants to ensure that only images that have been scanned and signed are deployed. They also want to prevent developers from accidentally using an unsigned image. Which approach should they implement?
Select an answer first - 50
What is the primary difference between SAST and DAST?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCSA” is a trademark of its owner, used for identification only.