
GIAC Cloud Security Automation
Domain 5Objective 3
Software Supply Chain Security GCSA Practice Questions (Page 5)
Part of the Identity, Secrets, and Supply Chain domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 3–5 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
8concepts
Questions 21–25
- 21
An organization wants to meet SLSA Level 2 requirements for its build process. The build currently runs on a developer's laptop and pushes artifacts directly to a production registry. Which change is necessary to satisfy SLSA Level 2?
Select an answer first - 22
A security team wants to automate the detection of known vulnerable components in their application before deployment. They have access to the application's dependency manifest. Which approach should they use?
Select an answer first - 23
A company is adopting NIST SSDF practices for its software development lifecycle. They currently have a CI/CD pipeline that builds artifacts, but they do not generate provenance or verify the integrity of third-party components. Which SSDF practice should they implement first to improve supply chain security?
Select an answer first - 24
A company's CI/CD pipeline uses a shared build cluster where multiple projects run builds on the same nodes. A security audit recommends isolating builds to reduce the risk of cross-project contamination. The team is considering using containerized build jobs. Which additional control is necessary to ensure that a compromised build cannot access other projects' secrets?
Select an answer first - 25
A company's CI/CD pipeline was compromised when an attacker gained access to a developer's account and modified the build script to exfiltrate secrets and inject malicious code into the produced artifacts. The malicious code was deployed to production before detection. The team has revoked the developer's access and removed the malicious code from the build script. What should be the next priority in the incident response?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCSA” is a trademark of its owner, used for identification only.