
GIAC Defensible Security Architect
Domain 5Objective 1
Cloud-Based Security Architecture GDSA Practice Questions (Page 7)
Part of the Cloud Security Architecture domain, which makes up ~10% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~5–8 in this domain), expect 5–8 from this objective — we provide 62 practice questions to prepare you well beyond it. (estimate)
62questions here
13free pages
14concepts
Questions 31–35
- 31
A company has a cloud environment and wants to detect and respond to security incidents. They need to collect logs from various cloud services, correlate them, and trigger automated responses. Which approach should they use?
Select an answer first - 32
A company is designing a multi-tier application in AWS. The web tier must be accessible from the internet, while the application and database tiers must be private. They also need to ensure that the database tier can only be accessed by the application tier. Which architecture should they use?
Select an answer first - 33
A company wants to implement single sign-on (SSO) for all their cloud applications. They currently use an on-premises identity provider. They also want to enforce MFA for all users. Which configuration should they use?
Select an answer first - 34
Which security architecture pattern assumes that no user or device is trusted by default, even if they are inside the network perimeter?
Select an answer first - 35
Which statement best describes the shared responsibility model in cloud security?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GDSA” is a trademark of its owner, used for identification only.