
GIAC Public Cloud Security
Domain 2Objective 1
Cloud Data Protection GPCS Practice Questions (Page 2)
Part of the Cloud Platform and Service Security domain, which makes up ~60% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~30–48 in this domain), expect 6–10 from this objective — we provide 55 practice questions to prepare you well beyond it. (estimate)
55questions here
11free pages
13concepts
Questions 6–10
- 6
A company stores sensitive customer data in Azure Blob Storage. The security team wants to detect when a large number of blobs are downloaded in a short period, which could indicate data exfiltration. They also need to retain the evidence for forensic analysis. What should they configure?
Select an answer first - 7
What is the purpose of a data retention policy?
Select an answer first - 8
Why is it important to enable logging for data access in cloud storage?
Select an answer first - 9
A financial services company stores customer account data in an AWS S3 bucket encrypted with SSE-S3. A new compliance mandate requires that the company retain direct control over the encryption keys and be able to rotate them independently of AWS. Which approach should the security team implement?
Select an answer first - 10
In which scenario is tokenization most commonly used?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GPCS” is a trademark of its owner, used for identification only.