Courseiva

GCIH · topic practice

Securing Credentials and Data in Cloud practice questions

This domain covers protecting credentials and data in cloud environments, focusing on AWS IAM, CloudTrail, Secrets Manager, and S3. Questions test detection of compromised access keys, IAM role trust misconfigurations like Confused Deputy, secret-scanning controls, and least-privilege enforcement during incident response.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Securing Credentials and Data in Cloud

What the exam tests

What to know about Securing Credentials and Data in Cloud

Be able to trace a leaked AWS access key through CloudTrail to GetSecretValue, explain Confused Deputy and external IDs, and apply least privilege. The most important thing: distinguish detection (CloudTrail) from prevention (scoped policies, secret scanning, external IDs).

Analyzing AWS CloudTrail events for GetSecretValue calls from unfamiliar IP addresses using compromised IAM access keys

Identifying Confused Deputy risks in cross-account IAM role trust policies and external ID requirements

Using secret-scanning tools like git-secrets or pre-commit hooks to block credential commits to repositories

Recognizing least privilege violations when AdministratorAccess is granted for routine operational IAM tasks

Watch out for

Common Securing Credentials and Data in Cloud exam traps

  • ▸Assuming CloudTrail alone blocks access-key abuse; it only logs API activity, so detection requires monitoring and alerting, not prevention.
  • ▸Confusing Confused Deputy with privilege escalation: the issue is a trusted service being tricked, not the user gaining direct permissions.
  • ▸Believing MFA on the IAM user prevents leaked access keys from working; long-term keys can still authenticate without MFA unless explicitly denied.

Practice set

Securing Credentials and Data in Cloud questions

20 questions · select your answer, then reveal the explanation

An incident responder discovers that an AWS IAM role associated with an EC2 instance has been used to exfiltrate sensitive data from an S3 bucket. The administrator wants to revoke all active sessions for this compromised role immediately without deleting the role itself. Which action should the responder take?

An incident responder discovers that an AWS IAM role utilized by an EC2 instance has been persistently leveraged to exfiltrate sensitive data from an Amazon S3 bucket. The security team needs to revoke all active sessions associated with this compromised role immediately without deleting the role itself. Which action achieves this objective effectively?

Which TWO of the following configurations are considered best practices for securing data at rest in a cloud environment?

Refer to the exhibit. An administrator applies this policy to an IAM user. The user reports they cannot list the contents of the 'company-data' bucket. What is the cause?

Exhibit

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": "s3:GetObject",
      "Resource": "arn:aws:s3:::company-data/*"
    }
  ]
}

An organization uses an Identity Provider (IdP) for Single Sign-On (SSO). How should they best handle the revocation of access for a terminated employee?

Which THREE actions should be taken to secure cloud-based API keys used by third-party integrations?

Refer to the exhibit. What is the effect of this policy on an IAM user who has NOT authenticated with MFA?

Exhibit

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Deny",
      "Action": "s3:*",
      "Resource": "*",
      "Condition": {
        "Bool": {
          "aws:MultiFactorAuthPresent": "false"
        }
      }
    }
  ]
}

Which of the following is the most secure way to manage database credentials for an application running on a cloud compute instance?

An incident responder discovers that an AWS IAM role associated with an EC2 instance has been compromised due to SSRF. The attacker has extracted temporary security credentials from the instance metadata service. Which immediate containment action prevents the attacker from continuing to use these stolen tokens while preserving forensic evidence on the running instance?

Refer to the exhibit. An incident responder reviews an AWS IAM policy attached to a compromised developer role. What security flaw is present in this policy definition?

Exhibit

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "s3:GetObject",
        "s3:PutObject"
      ],
      "Resource": "arn:aws:s3:::corporate-data-bucket/*"
    }
  ]
}

An incident responder discovers that an AWS IAM user's static access key was exposed in a public code repository. The security team needs to immediately revoke active sessions and prevent any ongoing unauthorized API calls using that credential without deleting the user account right away. Which action should the responder take?

An attacker has obtained a copy of an EC2 instance's IAM role credentials through a server-side request forgery (SSRF) vulnerability. The role currently has permissions to read and write to an S3 bucket containing sensitive customer data. The incident response team wants to immediately stop the active exfiltration while preserving forensic evidence. Which AWS action should they take FIRST?

An organization uses AWS Organizations with multiple accounts. A security analyst discovers that an IAM user in the development account was able to assume a role in the production account that grants full access to an S3 bucket containing customer PII. The role's trust policy allows assumption by any principal in the development account. Which AWS feature would have most effectively prevented this cross-account privilege escalation by restricting which principals can assume the production role?

A security team is investigating an incident where an attacker gained access to an AWS environment by using stolen long-term access keys. The keys belonged to a developer who had embedded them in a script that was later committed to a public GitHub repository. The team wants to prevent this from happening again. Which of the following is the MOST effective control to mitigate this risk?

A GCIH incident handler is responding to a security alert indicating that an AWS Lambda function's execution role credentials may have been compromised. The function has permissions to read from an S3 bucket containing sensitive data. Which TWO immediate actions should the handler take to contain the potential data exfiltration? (Choose two.)

An incident responder is investigating a breach in a Microsoft Azure environment. The attacker gained initial access by compromising a service principal that had been assigned the Contributor role at the subscription level. The service principal's credentials were stored in a configuration file on a compromised VM. Which TWO of the following actions should the responder take to contain the incident and prevent further unauthorized access? (Choose two.)

A company uses Google Cloud Platform (GCP) and has a requirement that all data stored in Cloud Storage buckets must be encrypted with customer-managed encryption keys (CMEK) to meet compliance. A security engineer needs to ensure that this requirement is enforced for all new buckets. Which of the following should the engineer implement?

An organization is migrating to AWS and needs to ensure that IAM users do not possess long-term credentials. Which approach provides the most secure mechanism for programmatic access?

When designing a secure cloud database, which configuration best protects against unauthorized data exfiltration if the database instance is misconfigured as public?

Which of the following describes the 'Confused Deputy' problem in the context of cloud IAM roles?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Securing Credentials and Data in Cloud sessions

Start a Securing Credentials and Data in Cloud only practice session

Every question in these sessions is drawn from the Securing Credentials and Data in Cloud domain — nothing else.

Related practice questions

Related GCIH topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the GCIH exam test about Securing Credentials and Data in Cloud?
Be able to trace a leaked AWS access key through CloudTrail to GetSecretValue, explain Confused Deputy and external IDs, and apply least privilege. The most important thing: distinguish detection (CloudTrail) from prevention (scoped policies, secret scanning, external IDs).
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Securing Credentials and Data in Cloud questions in a focused session?
Yes — the session launcher on this page draws every question from the Securing Credentials and Data in Cloud domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other GCIH topics?
Use the topic links above to move to related areas, or go back to the GCIH question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the GCIH exam covers. They are not copied from any real exam or dump site.