
GIAC Cloud Security Automation
Domain 5Objective 3
Software Supply Chain Security GCSA Practice Questions (Page 6)
Part of the Identity, Secrets, and Supply Chain domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 3–5 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
8concepts
Questions 26–30
- 26
In a supply chain incident response plan, what is the purpose of the eradication phase?
Select an answer first - 27
A software vendor wants to achieve SLSA Level 3 for their build process. They currently have a CI system that runs builds on shared agents and generates provenance attestations. Which additional requirement must they meet to reach SLSA Level 3?
Select an answer first - 28
What is an attestation in the context of software supply chain security?
Select an answer first - 29
A security team is evaluating a new third-party component for use in their application. They want to understand the component's dependencies and check for known vulnerabilities before approval. Which artifact should they request from the vendor?
Select an answer first - 30
Which practice is recommended to reduce the attack surface from third-party code?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCSA” is a trademark of its owner, used for identification only.