
GIAC Defensible Security Architect
Domain 5Objective 1
Cloud-Based Security Architecture GDSA Practice Questions (Page 1)
Part of the Cloud Security Architecture domain, which makes up ~10% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~5–8 in this domain), expect 5–8 from this objective — we provide 62 practice questions to prepare you well beyond it. (estimate)
62questions here
13free pages
14concepts
Questions 1–5
- 1
A security team wants to get a unified view of security posture across their AWS and Azure environments, including compliance with CIS benchmarks. Which tool should they use?
Select an answer first - 2
A team is deploying a Linux VM in Azure for a critical application. They need to ensure the VM is hardened against known vulnerabilities and that any new vulnerabilities are detected as soon as possible. Which Azure service should they use?
Select an answer first - 3
A company uses Azure and wants to collect security logs from multiple sources, including Azure AD, Azure Platform, and Office 365, and then analyze them for threats. Which service should they use?
Select an answer first - 4
Which compliance framework is specifically designed for organizations that handle credit card data?
Select an answer first - 5
A healthcare organization is storing patient data in a public cloud object storage service. They must encrypt the data at rest and control the encryption keys to meet compliance requirements. They also need to be able to revoke access to the data immediately if a key is compromised. Which key management strategy should they use?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GDSA” is a trademark of its owner, used for identification only.