
GIAC Public Cloud Security
Domain 2Objective 5
Securing Serverless Functions GPCS Practice Questions (Page 4)
Part of the Cloud Platform and Service Security domain, which makes up ~60% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~30–48 in this domain), expect 6–10 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)
48questions here
10free pages
12concepts
Questions 16–20
- 16
Which IAM practice is most effective for controlling what a serverless function can do to other cloud services?
Select an answer first - 17
What is a primary security risk associated with using third-party libraries in serverless functions?
Select an answer first - 18
A company is using AWS Lambda to process files from an S3 bucket and then send a notification to an SNS topic. The Lambda function's IAM role currently has AdministratorAccess. The security team wants to apply least privilege. What should they do?
Select an answer first - 19
A team deploys a Google Cloud Function that uses several open-source npm packages. The security team wants to reduce supply chain risk. Which approach should the team implement in their CI/CD pipeline?
Select an answer first - 20
Which practice best mitigates supply chain risks from third-party dependencies in serverless functions?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GPCS” is a trademark of its owner, used for identification only.