
GIAC Cloud Security Automation
Domain 3Objective 4
Workload Security in Container Orchestration GCSA Practice Questions (Page 2)
Part of the Container Orchestration Architecture and Security domain, which makes up ~19% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–15 in this domain), expect 3–4 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)
43questions here
9free pages
8concepts
Questions 6–10
- 6
A microservice needs to authenticate to an external API using OAuth2 client credentials. The client secret is stored in a Kubernetes Secret. You want to minimize the risk of secret exposure. Which approach is the most secure?
Select an answer first - 7
What is the primary purpose of a Pod Security Policy (PSP) in Kubernetes?
Select an answer first - 8
What is the primary purpose of setting resource limits on a container in Kubernetes?
Select an answer first - 9
You have a three-tier application: web, app, and db. The web tier must accept traffic from the internet, the app tier only from the web tier, and the db tier only from the app tier. Which NetworkPolicy design meets these requirements?
Select an answer first - 10
You have a Kubernetes cluster with a frontend service, a backend service, and a legacy database pod. The frontend must talk only to the backend, the backend only to the database, and the database must not initiate outbound connections. Which NetworkPolicy configuration satisfies these requirements?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCSA” is a trademark of its owner, used for identification only.