Group Purchasing
Group Purchasing

What Is the GCSA Certification?

The GIAC Cloud Security Automation (GCSA) certification validates a practitioner's understanding of the cloud native toolchain, DevSecOps methodology, and security controls throughout CI/CD pipelines. Certification holders have demonstrated the tools and skills needed to implement configurations that improve the reliability, integrity, and security of cloud native systems.

By the numbers

2 hrs

Exam duration

75

Questions

66%

Min. passing score

What GCSA Covers

The objectives group into 5 practical domains matching the course's five sections.

DevOps Workflow Security

Understanding the DevOps Workflow, Securing the DevOps Workflow, and Managing Secrets.

Infrastructure and Supply Chain

Deploying Cloud Infrastructure as Code, Utilizing Configuration Management, Container Lifecycle Security, and Software Supply Chain Security.

Container Orchestration Security

Architecture and Fundamentals of Container Orchestration, Risks, Authentication, and Access-Control of Container Orchestration, Workload Security in Container Orchestration, and Runtime Security in Container Orchestration.

Microservice and Edge Security

Edge Identity and Authentication, Microservice API Gateways, Microservices Architecture and Deployment, and Cloud Native Observability.

Compliance and Automated Remediation

Cloud Compliance as Code, Policy Enforcement, and Automated Cloud Remediation.

Prepare With This Course

SEC540: Cloud Native Security and DevSecOps Automation

How SEC540 Prepares You for GCSA

SEC540 is built around the exam objectives that make up the GCSA certification: 

  • Section 1, DevOps Security Automation builds skills tested under Understanding the DevOps Workflow, Securing the DevOps Workflow, and Managing Secrets.
  • Section 2, Cloud Infrastructure Security aligns with Deploying Cloud Infrastructure as Code, Utilizing Configuration Management, Container Lifecycle Security, and Software Supply Chain Security.
  • Section 3, Cloud Native Security Operations builds skills tested under Architecture and Fundamentals of Container Orchestration, Risks, Authentication, and Access-Control of Container Orchestration, Workload Security in Container Orchestration, and Runtime Security in Container Orchestration.
  • Section 4, Microservice Security aligns with Edge Identity and Authentication, Microservice API Gateways, Microservices Architecture and Deployment, and Cloud Native Observability.
  • Section 5, Continuous Compliance builds skills tested under Cloud Compliance as Code, Policy Enforcement, and Automated Cloud Remediation.

Across all five sections, 19 hands-on labs give you the chance to apply each control in live AWS or Azure environments before you sit the exam. Optional CloudWars bonus challenges each day add extra practice for students who want to go further. 

Read the full GCSA certification overview 

SEC540 Author

Eric Johnson
Eric Johnson

Eric Johnson

Principal Security Engineer at Puma Security

Eric Johnson is a Fellow at the SANS Institute and Principal Security Engineer at Puma Security. He leads hands-on training in SEC540: Cloud Native Security and DevSecOps Automation, co-authors SEC549 and SEC510, and develops open-source tools to help practitioners secure cloud pipelines.

Read more about Eric Johnson

Who Should Pursue GCSA

Developers and Software Architects

Operations Engineers and System Administrators

Security Analysts, Engineers, and Consultants

Auditors and Risk Managers

Anyone working in a public cloud or DevOps environment

Frequently Asked Questions

The GIAC Cloud Security Automation (GCSA) certification validates a practitioner's understanding of the cloud native toolchain, DevSecOps methodology, and security controls throughout CI/CD pipelines. Certification holders have demonstrated the tools and skills needed to implement configurations that improve the reliability, integrity, and security of cloud native systems.

The GCSA exam is a single 2-hour, 75-question, proctored test with a minimum passing score of 66%

GIAC certifications are renewed on a recurring cycle through continuing education credits and a maintenance fee. For the current renewal requirements, see GIAC’s renewal page

GCSA is built for developers and software architects, operations engineers and system administrators, security analysts, engineers, and consultants, auditors and risk managers, and anyone working in a public cloud or DevOps environment.

SEC540: Cloud Native Security and DevSecOps Automation prepares you for it through 19 hands-on labs covering the DevOps toolchain, cloud infrastructure, Kubernetes, microservices, and continuous compliance, with optional CloudWars bonus challenges each day for extra practice.

Ready to earn your GSCA certification?

Add the GSCA exam attempt when you register for SEC540.

Already trained? Register for the exam directly through GIAC here.

GCSA Certification | Cloud Security Automation | SANS Institute