
GIAC Cloud Security Automation
Domain 3Objective 4
Workload Security in Container Orchestration GCSA Practice Questions (Page 8)
Part of the Container Orchestration Architecture and Security domain, which makes up ~19% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–15 in this domain), expect 3–4 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)
43questions here
9free pages
8concepts
Questions 36–40
- 36
Your organization runs a multi-tenant Kubernetes cluster where each team deploys workloads into shared namespaces. The security team wants to ensure that no workload can run with root privileges, escalate privileges, or mount host paths, while still allowing teams to deploy standard web applications. Which approach should you use?
Select an answer first - 37
A Kubernetes cluster runs multiple teams in shared namespaces. One team's workload is consuming excessive memory, causing other pods to be evicted. The cluster administrator wants to prevent this without affecting the other teams' workloads. What should be configured?
Select an answer first - 38
In Kubernetes, what is the default behavior for network traffic between pods if no NetworkPolicy is defined?
Select an answer first - 39
What is the purpose of scanning container images for vulnerabilities?
Select an answer first - 40
A development team needs to deploy a microservice that reads a database password and calls an internal API using a service account token. The cluster uses Kubernetes RBAC and the team wants to avoid hardcoding credentials in the container image. Which approach should you recommend?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCSA” is a trademark of its owner, used for identification only.