
GIAC Public Cloud Security
Domain 2Objective 5
Securing Serverless Functions GPCS Practice Questions (Page 9)
Part of the Cloud Platform and Service Security domain, which makes up ~60% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~30–48 in this domain), expect 6–10 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)
48questions here
10free pages
12concepts
Questions 41–45
- 41
What is a key challenge when performing forensic analysis on serverless functions?
Select an answer first - 42
A team is developing a serverless function that uses several open-source npm packages. The security team wants to reduce the risk of supply chain attacks before the function is deployed. Which approach is most effective?
Select an answer first - 43
How should a serverless function retrieve a database password at runtime?
Select an answer first - 44
What is the purpose of enabling monitoring and alerting for serverless functions?
Select an answer first - 45
A developer wrote an Azure Function that accepts a JSON payload from an HTTP trigger, extracts a 'name' field, and inserts it into a SQL database using parameterized queries. The function also logs the raw payload to Application Insights. A security review flags a risk. What should the developer change?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GPCS” is a trademark of its owner, used for identification only.