
GIAC Cloud Security Automation
Domain 3Objective 4
Workload Security in Container Orchestration GCSA Practice Questions (Page 9)
Part of the Container Orchestration Architecture and Security domain, which makes up ~19% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–15 in this domain), expect 3–4 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)
43questions here
9free pages
8concepts
Questions 41–43
- 41
A microservice needs to access the Kubernetes API to list pods in its namespace. You want to grant the least privilege necessary. Which configuration should you use?
Select an answer first - 42
A security operations team is investigating a potential container compromise. The runtime security tool has alerted on a process executing a binary that is not in the image's layer history. The image was scanned and signed at build time. Which action should the team take first?
Select an answer first - 43
A company uses a private container registry and wants to ensure that only signed, vulnerability-free images are deployed to production. They have a CI pipeline that builds and scans images. What additional control should be added to enforce this at deployment time?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GCSA
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCSA” is a trademark of its owner, used for identification only.