
GIAC Public Cloud Security
Domain 2Objective 2
Cloud Identity and Access Management GPCS Practice Questions (Page 10)
Part of the Cloud Platform and Service Security domain, which makes up ~60% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~30–48 in this domain), expect 6–10 from this objective — we provide 59 practice questions to prepare you well beyond it. (estimate)
59questions here
12free pages
12concepts
Questions 46–50
- 46
A company uses Azure AD and has a high turnover of contractors. The security team wants to ensure that when a contractor's employment ends, their access to Azure resources is removed automatically. Which approach should be used?
Select an answer first - 47
A company uses Okta as its identity provider and wants employees to access AWS resources using their existing corporate credentials. The company requires that MFA be enforced for all AWS console access. What should the company configure?
Select an answer first - 48
What is the primary purpose of IAM monitoring and auditing in the cloud?
Select an answer first - 49
A company uses Azure AD as its identity provider and wants to allow employees to access AWS resources. They have a requirement that MFA must be enforced, and they want to avoid maintaining separate AWS credentials. Additionally, they need to map Azure AD groups to AWS IAM roles for permissions. What should they configure?
Select an answer first - 50
What is the purpose of deprovisioning in identity lifecycle management?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GPCS” is a trademark of its owner, used for identification only.