GCSA Exam - ID 12674220 -
GIAC Cloud Security
Automation exam with
complete solutions
This feature is available with Azure Firewall but is not supported by
Network Security Groups - answer Network Address Translation support
This needs to be added to an azure content delivery network to enable
token authentication - answer Encryption Key
for security automation tasks in devops processes we rely on this for
reactive programming to react to changes in cloud resources where you
can take necessary security actions - answer event grid
service account keys, SSH keys, API keys aka "secret keys" are disclosed
by implementing this - answer IaC
RASP - answer Runtime Application Security / Self Protection
Runtime overhead is introduced, affecting CPU, memory and latency due
to this - answer RASP
a set of automated security assertions and tests should be run after code
changes are deployed. these tests are called - answer smoke tests
When terraform code WAFPolicy is set to "Prevention" mode ... - answer
rule severity is correlated to an anomaly score before traffic is blocked
, in terraform WAF policy anomaly scoring, rule severity considers - answer
critical, error, warning or notice
in terraform WAF policy "prevention mode" for something to be blocked it
must score - answer 5
terraform WAF policy "prevention" mode score 5 - answer critical
terraform WAF policy "prevention" mode score 3 - answer warning
prior to terraform waf policy 3.1 any traffic that matches the rule triggers
this regardless of any other context . this is "traditional Mode" found in
CRS versions - answer block
DAST - answer Dynamic Application Security Testing
if a scanner is crawling a web page gathering HTTP GET responses to
"observe" the web application's behaviour this is what type of security
testing - answer Passive DAST
Active DAST - answer sending malicious data to the application to see
how it will respond
Active DAST is also called - answer fuzzing
DAST scans can be run in two ways - answer manual or automated: GUI
or command for manual.
DAST "headless" scans - answer these are automated possibly as part of
the dev pipeline
InSpec - answer this tool might be used to inspect an SSH configuration
GIAC Cloud Security
Automation exam with
complete solutions
This feature is available with Azure Firewall but is not supported by
Network Security Groups - answer Network Address Translation support
This needs to be added to an azure content delivery network to enable
token authentication - answer Encryption Key
for security automation tasks in devops processes we rely on this for
reactive programming to react to changes in cloud resources where you
can take necessary security actions - answer event grid
service account keys, SSH keys, API keys aka "secret keys" are disclosed
by implementing this - answer IaC
RASP - answer Runtime Application Security / Self Protection
Runtime overhead is introduced, affecting CPU, memory and latency due
to this - answer RASP
a set of automated security assertions and tests should be run after code
changes are deployed. these tests are called - answer smoke tests
When terraform code WAFPolicy is set to "Prevention" mode ... - answer
rule severity is correlated to an anomaly score before traffic is blocked
, in terraform WAF policy anomaly scoring, rule severity considers - answer
critical, error, warning or notice
in terraform WAF policy "prevention mode" for something to be blocked it
must score - answer 5
terraform WAF policy "prevention" mode score 5 - answer critical
terraform WAF policy "prevention" mode score 3 - answer warning
prior to terraform waf policy 3.1 any traffic that matches the rule triggers
this regardless of any other context . this is "traditional Mode" found in
CRS versions - answer block
DAST - answer Dynamic Application Security Testing
if a scanner is crawling a web page gathering HTTP GET responses to
"observe" the web application's behaviour this is what type of security
testing - answer Passive DAST
Active DAST - answer sending malicious data to the application to see
how it will respond
Active DAST is also called - answer fuzzing
DAST scans can be run in two ways - answer manual or automated: GUI
or command for manual.
DAST "headless" scans - answer these are automated possibly as part of
the dev pipeline
InSpec - answer this tool might be used to inspect an SSH configuration