Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Public Cloud Security

Domain 2Objective 3

Securing Cloud Application Service Platforms GPCS Practice Questions (Page 6)

Part of the Cloud Platform and Service Security domain, which makes up ~60% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~30–48 in this domain), expect 6–10 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)

37questions here
8free pages
7concepts

Questions 26–30

  1. 26expert · medium

    A financial services company must comply with PCI DSS and GDPR. The company uses a cloud application service platform that stores personal data of EU citizens. The compliance team requires that data be encrypted at rest and that access to the data be logged. The company also needs to demonstrate compliance to auditors. Which approach best meets these requirements?

    Select an answer first
  2. 27expert · medium

    A multinational company uses a cloud application service platform with multiple business units. Each business unit has its own application services and data. The security team wants to enforce least privilege while allowing each business unit to manage its own resources. The company also needs to meet regulatory requirements that require separation of duties. Which approach best satisfies these requirements?

    Select an answer first
  3. 28application · medium

    A company's application service processes sensitive customer data. The security team wants to ensure that data is encrypted in transit between the application service and the database, and that the database connection string is not stored in the application's configuration file. What should the security team implement?

    Select an answer first
  4. 29expert · hard

    A security operations team is investigating a potential data breach in a cloud application service. They have access to the platform's logs, but the logs are incomplete for the time period of the suspected breach. They need to determine what happened. Which action should they take first?

    Select an answer first
  5. 30expert · hard

    A company runs a microservices-based application on a cloud application service platform. Each microservice needs to communicate with others, but the security team wants to minimize the attack surface by restricting communication to only necessary services. They also need to detect any anomalous traffic between services. Which approach should they implement?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GPCS” is a trademark of its owner, used for identification only.