
GIAC Defensible Security Architect
Domain 5Objective 1
Cloud-Based Security Architecture GDSA Practice Questions (Page 2)
Part of the Cloud Security Architecture domain, which makes up ~10% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~5–8 in this domain), expect 5–8 from this objective — we provide 62 practice questions to prepare you well beyond it. (estimate)
62questions here
13free pages
14concepts
Questions 6–10
- 6
A company wants to automate the remediation of common cloud misconfigurations, such as leaving security groups open to the world. They want to fix these issues without manual intervention. Which capability should they use?
Select an answer first - 7
A company wants to keep sensitive data in its own data center while using cloud resources for non-sensitive processing. Which deployment model best fits this requirement?
Select an answer first - 8
Which cloud service is typically used to collect and analyze logs from various cloud resources for security monitoring?
Select an answer first - 9
A company is using a SaaS application for email. They want to ensure that their data is protected and that they can meet compliance requirements. Which responsibility is most likely the customer's?
Select an answer first - 10
A company is adopting a zero-trust architecture for their cloud environment. They want to ensure that every access request is authenticated and authorized, regardless of the user's location. They also need to minimize the risk of lateral movement. Which approach should they implement?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GDSA” is a trademark of its owner, used for identification only.