
GIAC Security Leadership
Domain 2Objective 3
Managing Cloud Security GSLC Practice Questions (Page 7)
Part of the Technical Security Management domain, which makes up ~27% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~19–32 in this domain), expect 4–6 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)
49questions here
10free pages
7concepts
Questions 31–35
- 31
A company is evaluating two cloud providers for a new application. Provider A offers a lower price but has limited security certifications. Provider B is more expensive but has comprehensive security certifications and a strong audit trail. The company's compliance team requires that the provider have ISO 27001 certification. Which provider should the company choose?
Select an answer first - 32
A company is selecting a cloud provider for a new project. The security team has identified that the provider's data centers are located in a country with different privacy laws than the company's home country. Which contractual clause is most important to include in the agreement?
Select an answer first - 33
A company is designing a hybrid cloud architecture. The company has a legacy application that must remain on-premises due to latency requirements, but it wants to extend its compute capacity to the cloud for burst workloads. The security architect must ensure that the cloud resources can securely communicate with the on-premises network. The company is concerned about exposing the on-premises network to the cloud. What should the architect implement?
Select an answer first - 34
A company's cloud environment has been compromised. The incident response team has identified that the attacker used a compromised administrative account. The team needs to contain the incident while preserving evidence. Which action should the team take first?
Select an answer first - 35
A company is moving its customer relationship management (CRM) system to a cloud-based software-as-a-service (SaaS) offering. The company's security team must understand which security controls are the provider's responsibility. Which control is typically the provider's responsibility in a SaaS model?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSLC” is a trademark of its owner, used for identification only.