Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Cloud Security Automation

Domain 5Objective 3

Software Supply Chain Security GCSA Practice Questions (Page 9)

Part of the Identity, Secrets, and Supply Chain domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 3–5 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)

50questions here
10free pages
8concepts

Questions 41–45

  1. 41application · medium

    A company's CI/CD pipeline builds container images using a shared, long-lived build agent that has broad permissions to the production registry. After a supply chain incident, the security team wants to reduce the blast radius of a compromised build. Which change best aligns with SLSA Level 2 principles?

    Select an answer first
  2. 42application · medium

    A security team discovers that a popular open-source library used by multiple internal applications was compromised. The library's maintainer account was hijacked, and a malicious version was published to the public registry. The team's applications use a lock file that pins the library to a specific version. What is the immediate risk and the best first response?

    Select an answer first
  3. 43application · medium

    A software vendor wants to provide customers with verifiable evidence that a released binary was built from the exact source code in their repository and that the build process was not tampered with. The vendor already signs the binary with its private key. What additional control should the vendor implement to meet this goal?

    Select an answer first
  4. 44application · medium · select all that apply

    A security analyst is using an SBOM to assess the risk of a new application. The SBOM lists several direct and transitive dependencies. Select all that apply to properly use the SBOM.

    Select an answer first
  5. 45expert · hard

    A security incident is declared after a malicious dependency is found in a production application. The malicious dependency was introduced through a direct dependency that was updated by a developer two weeks ago. The team has identified the malicious package and removed it from the registry. Which sequence of actions best follows the incident response phases of containment, eradication, and recovery?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCSA” is a trademark of its owner, used for identification only.