
GIAC Cloud Security Automation
Domain 5Objective 3
Software Supply Chain Security GCSA Practice Questions (Page 10)
Part of the Identity, Secrets, and Supply Chain domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 3–5 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
8concepts
Questions 46–50
- 46
A company wants to generate and verify provenance for its software artifacts to meet SLSA Level 2. The build runs on a hosted CI/CD service. Select all that apply.
Select an answer first - 47
A company discovers that a malicious package was published to their internal package registry and was used as a dependency in several applications. The malicious package has been removed from the registry, but the company needs to ensure that no application is still running with the compromised code. Which combination of actions should the incident response team take?
Select an answer first - 48
What is the primary purpose of provenance metadata in a software supply chain?
Select an answer first - 49
A developer downloads a third-party library directly from a website using HTTPS. The website provides a SHA-256 checksum on the download page. The developer wants to ensure the file has not been tampered with during download. Which step should the developer take?
Select an answer first - 50
When downloading a container image, what does verifying its cryptographic hash ensure?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GCSA
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCSA” is a trademark of its owner, used for identification only.