
GIAC Public Cloud Security
Domain 2Objective 5
Securing Serverless Functions GPCS Practice Questions (Page 8)
Part of the Cloud Platform and Service Security domain, which makes up ~60% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~30–48 in this domain), expect 6–10 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)
48questions here
10free pages
12concepts
Questions 36–40
- 36
A company is deploying an AWS Lambda function that processes S3 uploads and writes results to DynamoDB. The function needs to access the DynamoDB table and also needs to call an external API using a secret API key. The security team requires that the function never have access to any AWS credentials in the code or environment variables. What is the most secure way to provide the necessary access?
Select an answer first - 37
Why is logging important for serverless functions from a security perspective?
Select an answer first - 38
Which practice helps ensure data privacy when a serverless function handles sensitive data?
Select an answer first - 39
A security analyst needs to detect a potential data exfiltration attempt from a serverless function that reads from a database and writes to S3. The function uses an IAM role. Which combination of actions would provide the most useful evidence?
Select an answer first - 40
What is the purpose of output encoding in a serverless function?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GPCS” is a trademark of its owner, used for identification only.