
GIAC Public Cloud Security
Domain 1Objective 1
Multicloud and Credential Management Fundamentals GPCS Practice Questions (Page 4)
Part of the Cloud Security Fundamentals domain, which makes up ~21% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~11–17 in this domain), expect 6–9 from this objective — we provide 35 practice questions to prepare you well beyond it. (estimate)
35questions here
7free pages
5concepts
Questions 16–20
- 16
A company uses AWS and Azure. The security team wants to implement a solution that automatically rotates database credentials for applications running in both clouds. The applications are deployed on EC2 instances in AWS and Azure VMs. Which solution is most effective?
Select an answer first - 17
A company must comply with a regulation that requires all access to production credentials to be logged and reviewed. The company uses a centralized secrets manager. Which control is most effective for meeting the review requirement?
Select an answer first - 18
A startup uses AWS and Azure. Developers need temporary credentials to access resources in both clouds from their local machines. The company wants to avoid storing long-lived access keys on developer laptops. Which approach best meets this requirement?
Select an answer first - 19
A company is considering a multicloud strategy to avoid vendor lock-in. The CTO wants to ensure that identity and access management (IAM) policies are portable across clouds. Which approach best supports this goal?
Select an answer first - 20
A company is implementing a credential lifecycle policy. Which set of stages, in the correct order, represents the credential lifecycle?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GPCS” is a trademark of its owner, used for identification only.