
GIAC Information Security Fundamentals
Domain 2Objective 3
Securing Connected and Cloud-Based Environments GISF Practice Questions (Page 10)
Part of the Network and Systems Security domain, which makes up ~28% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~14–22 in this domain), expect 5–7 from this objective — we provide 54 practice questions to prepare you well beyond it. (estimate)
54questions here
11free pages
8concepts
Questions 46–50
- 46
A healthcare startup wants to run its patient-facing web application in the cloud. They need to reduce administrative overhead for patching the operating system, but they also need to ensure the underlying infrastructure meets HIPAA security requirements. Which cloud service model best fits these needs?
Select an answer first - 47
A company stores sensitive customer data in a cloud object storage service. They want to protect the data at rest and also control who can decrypt it. They require that the cloud provider cannot access the encryption keys. Which key management approach should they use?
Select an answer first - 48
An organization uses a cloud-based project management tool. They want to ensure that only authorized users can access it and that each user's actions are traceable. Which combination of controls is most effective?
Select an answer first - 49
What is the primary advantage of using a cloud key management service (KMS) over storing encryption keys directly with the encrypted data?
Select an answer first - 50
Which identity and access management concept is used to grant users temporary, limited-privilege credentials to access cloud resources without storing long-term secrets?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GISF” is a trademark of its owner, used for identification only.