GCIH · domain
Securing Credentials and Data in Cloud
This domain covers protecting credentials and data in cloud environments, focusing on AWS IAM, CloudTrail, Secrets Manager, and S3. Questions test detection of compromised access keys, IAM role trust misconfigurations like Confused Deputy, secret-scanning controls, and least-privilege enforcement during incident response.
Focused practice
Practice Securing Credentials and Data in Cloud questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Securing Credentials and Data in Cloud
Be able to trace a leaked AWS access key through CloudTrail to GetSecretValue, explain Confused Deputy and external IDs, and apply least privilege. The most important thing: distinguish detection (CloudTrail) from prevention (scoped policies, secret scanning, external IDs).
Analyzing AWS CloudTrail events for GetSecretValue calls from unfamiliar IP addresses using compromised IAM access keys
Identifying Confused Deputy risks in cross-account IAM role trust policies and external ID requirements
Using secret-scanning tools like git-secrets or pre-commit hooks to block credential commits to repositories
Recognizing least privilege violations when AdministratorAccess is granted for routine operational IAM tasks
Watch out for
Common Securing Credentials and Data in Cloud exam traps
- ▸Assuming CloudTrail alone blocks access-key abuse; it only logs API activity, so detection requires monitoring and alerting, not prevention.
- ▸Confusing Confused Deputy with privilege escalation: the issue is a trusted service being tricked, not the user gaining direct permissions.
- ▸Believing MFA on the IAM user prevents leaked access keys from working; long-term keys can still authenticate without MFA unless explicitly denied.
Question index
All Securing Credentials and Data in Cloud questions (15)
Click any question to see the full explanation, or start a practice session above.
A security analyst is investigating a suspected compromise of an AWS environment. The analyst discovers that an IAM user's access key was used from an unknown IP address to enumerate S3 buckets and download objects. The analyst needs to secure the environment and gather evidence. Which TWO actions should the analyst take to both contain the incident and preserve forensic data? (Choose two.)
Hard2An incident responder discovers an EC2 instance in AWS has been compromised via a web application vulnerability. The instance profile attached to the instance has broad administrative permissions. What is the immediate priority to contain credential compromise in this scenario?
Medium3Which feature is most effective for preventing the accidental upload of secrets to a public cloud source code repository?
Medium4An incident responder is analyzing a compromised AWS EC2 instance that was used to exfiltrate data from an S3 bucket. The attacker gained access by exploiting a server-side request forgery (SSRF) vulnerability in a web application running on the instance. The instance had an IAM role attached that allowed s3:GetObject on a sensitive bucket. Which of the following logs would provide the MOST direct evidence of the S3 data access by the attacker?
Hard5When designing a secure cloud database, which configuration best protects against unauthorized data exfiltration if the database instance is misconfigured as public?
Medium6A security team is configuring encryption for data at rest in an Amazon S3 bucket that stores regulated financial records. They need to ensure that the encryption keys are managed by the organization and can be rotated on demand, while also providing an audit trail of key usage. Which AWS service should they use to meet these requirements?
Easy7An incident responder is analyzing a potential compromise of an AWS environment. The attacker gained access to an EC2 instance and then used the instance's IAM role to call the AWS Security Token Service (STS) AssumeRole API to obtain credentials for a role in another account. The attacker then used those credentials to access sensitive data. Which AWS service or feature would provide the most detailed log of the AssumeRole API call, including the identity of the caller and the target role?
Hard8A security analyst is reviewing access to a cloud-based file storage service. The organization uses SAML-based single sign-on (SSO) with an external identity provider (IdP) for authentication. The analyst notices that some users are still able to access the file storage service using their old username and password, even after SSO was enforced. Which of the following is the MOST likely cause?
Medium9A GCIH responder is investigating a compromised AWS account where an EC2 instance's IAM role credentials were stolen from the instance metadata service. The attacker used those temporary credentials from an external IP address to download sensitive objects from an S3 bucket. Which AWS service or mechanism would have provided the earliest detection of this specific anomalous behavior?
Medium10An incident responder is analyzing a potential compromise in an AWS environment. The responder notices that an IAM role attached to an EC2 instance has been used to access an S3 bucket from an external IP address. The role's trust policy allows the EC2 service to assume it. Which technique is the attacker MOST likely using to abuse this role?
Hard11During a cloud incident response engagement, an analyst reviews AWS CloudTrail logs and finds that an access key belonging to an IAM user was used from an unfamiliar IP address to call GetSecretValue against AWS Secrets Manager. The key is still active. Which immediate containment action best limits further credential misuse while preserving the ability to investigate who used the key?
Hard12Which security principle is violated when an IAM user is assigned the 'AdministratorAccess' policy for daily operational tasks?
Easy13An organization is migrating to AWS and needs to ensure that IAM users do not possess long-term credentials. Which approach provides the most secure mechanism for programmatic access?
Medium14A company stores sensitive data in an Amazon S3 bucket. The security team wants to ensure that all data is encrypted at rest using keys managed by AWS Key Management Service (KMS) and that the encryption is enforced automatically for all new objects. Which configuration should they implement?
Medium15Which of the following describes the 'Confused Deputy' problem in the context of cloud IAM roles?
HardOther domains
All GCIH exam domains
Frequently asked questions
- What does the Securing Credentials and Data in Cloud domain cover on the GCIH exam?
- Be able to trace a leaked AWS access key through CloudTrail to GetSecretValue, explain Confused Deputy and external IDs, and apply least privilege. The most important thing: distinguish detection (CloudTrail) from prevention (scoped policies, secret scanning, external IDs).
- How many questions are in this domain?
- This page lists all 15 Securing Credentials and Data in Cloud questions in the GCIH question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Securing Credentials and Data in Cloud questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.