
GIAC Cloud Security Automation
Domain 5Objective 3
Software Supply Chain Security GCSA Practice Questions (Page 7)
Part of the Identity, Secrets, and Supply Chain domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 3–5 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
8concepts
Questions 31–35
- 31
A security team wants to identify which of their deployed applications are affected by a newly disclosed vulnerability in a popular logging library. The team has access to the container images stored in their registry. Which approach should they use to quickly determine affected applications?
Select an answer first - 32
A security team is reviewing the CI/CD pipeline for a web application. The pipeline currently runs on a shared build server with a single service account that has access to the production environment. The team wants to implement least privilege and isolate build environments. Select all that apply.
Select an answer first - 33
A company's security team has identified that a malicious version of a build tool was used in their CI/CD pipeline for the past month. The team needs to determine which released artifacts were affected. Which data source should they use?
Select an answer first - 34
What is the purpose of applying the principle of least privilege to a CI/CD pipeline?
Select an answer first - 35
What is the primary goal of the SLSA framework?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCSA” is a trademark of its owner, used for identification only.