
GIAC Cloud Security Automation
Domain 1Objective 2
Securing the DevOps Workflow GCSA Practice Questions (Page 3)
Part of the DevOps and Cloud Infrastructure domain, which makes up ~24% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~12–19 in this domain), expect 3–5 from this objective — we provide 52 practice questions to prepare you well beyond it. (estimate)
52questions here
11free pages
10concepts
Questions 11–15
- 11
A company has a microservices architecture deployed on Kubernetes. The security team wants to detect and respond to a potential security incident where an attacker might be moving laterally between pods. They have a SIEM that collects logs from the cluster. Which practice should they implement to improve detection?
Select an answer first - 12
A development team wants to integrate automated security testing into their CI pipeline for a Java application. They need to catch vulnerabilities in the source code, in third-party libraries, and in the final container image. Which set of tools should they add to the pipeline?
Select an answer first - 13
What is a key consideration when responding to a security incident in a containerized environment?
Select an answer first - 14
Why is automated rotation of secrets important in a DevOps workflow?
Select an answer first - 15
What is a key security benefit of using configuration management tools in a DevOps environment?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCSA” is a trademark of its owner, used for identification only.