
GIAC Public Cloud Security
Domain 2Objective 5
Securing Serverless Functions GPCS Practice Questions (Page 2)
Part of the Cloud Platform and Service Security domain, which makes up ~60% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~30–48 in this domain), expect 6–10 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)
48questions here
10free pages
12concepts
Questions 6–10
- 6
Why should vulnerability scanning of dependencies be part of the CI/CD pipeline for serverless functions?
Select an answer first - 7
What is the purpose of data minimization in serverless functions?
Select an answer first - 8
A company suspects that a malicious actor exploited a vulnerability in a Google Cloud Function. The function is stateless and uses Cloud Storage for input and output. The incident response team needs to collect forensic evidence. What should they do first?
Select an answer first - 9
A security team is investigating a potential compromise of an AWS Lambda function. They suspect that the function's IAM role was used to access an S3 bucket that it should not have had access to. The team has CloudTrail enabled, but they are not sure if the relevant events were captured. What should they check first?
Select an answer first - 10
Which control is specifically designed to protect a serverless function from being overwhelmed by a sudden spike in invocations?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GPCS” is a trademark of its owner, used for identification only.