Unit 5: Compliance and Cloud Security Operations - Practice Quiz

INT244 — Securing Computing Systems 60 Questions
0 Correct 0 Wrong 60 Left
0/60

1 What is the main purpose of compliance in a Security Operations Center (SOC)?

Compliance and Regulatory Considerations in SOC: introduction Easy
A. To meet required security rules
B. To replace all security staff
C. To increase internet speed
D. To reduce software features

2 Why can regulatory compliance be difficult for organizations operating in multiple countries?

Compliance and Regulatory Considerations in SOC: regulatory challenges across geographies Easy
A. Cloud services cannot operate across borders
B. All countries use identical privacy laws
C. Different countries have different requirements
D. International systems never store personal data

3 What type of information is commonly protected by healthcare data regulations?

Compliance and Regulatory Considerations in SOC: healthcare data breaches Easy
A. Unrelated entertainment files
B. Office furniture records
C. Patient health information
D. Public weather forecasts

4 What should a healthcare organization do after discovering a reportable data breach?

Compliance and Regulatory Considerations in SOC: healthcare data breaches Easy
A. Publish every internal system password
B. Delete all security monitoring records
C. Wait until the issue is forgotten
D. Follow required breach notification procedures

5 What is a key security concern for financial services organizations?

Compliance and Regulatory Considerations in SOC: financial services data security Easy
A. Protecting customer financial data
B. Allowing unrestricted account access
C. Disabling authentication for employees
D. Removing all transaction records

6 Which control helps protect access to financial systems?

Compliance and Regulatory Considerations in SOC: financial services data security Easy
A. Shared administrator passwords
B. Multi-factor authentication
C. Unrestricted public access
D. Disabled access logging

7 Why is incident response important for energy and utility organizations?

Compliance and Regulatory Considerations in SOC: energy and utility incident response Easy
A. Response plans eliminate every possible attack
B. Utilities do not use computer systems
C. Security incidents only affect office design
D. Incidents can affect critical services

8 What is an important first activity during an incident involving a utility system?

Compliance and Regulatory Considerations in SOC: energy and utility incident response Easy
A. Ignore the event until normal operations return
B. Assess the incident and contain its impact
C. Immediately erase all affected system evidence
D. Allow every device to connect without restrictions

9 What is the purpose of a continuous incident readiness assessment?

Compliance and Regulatory Considerations in SOC: continuous incident readiness assessments Easy
A. To remove the need for incident response plans
B. To check whether response capabilities remain effective
C. To replace security testing with informal discussions
D. To permanently stop all network communication

10 Which activity can help test an organization's incident readiness?

Compliance and Regulatory Considerations in SOC: continuous incident readiness assessments Easy
A. Removing emergency contact information
B. Ignoring previously reported incidents
C. Conducting a tabletop exercise
D. Avoiding updates to response procedures

11 What does a SIEM system commonly do with security logs?

Compliance and Regulatory Considerations in SOC: role of SIEM in achieving compliance Easy
A. Collects and analyzes logs
B. Physically repairs damaged servers
C. Creates employee identity documents
D. Replaces all network devices

12 How can a SIEM support compliance audits?

Compliance and Regulatory Considerations in SOC: role of SIEM in achieving compliance Easy
A. By storing only unverified events without timestamps
B. By preventing every security incident
C. By providing searchable security records
D. By removing the need for written policies

13 What is cloud security primarily concerned with protecting?

Cloud Security and SOC Operations: introduction Easy
A. Only the physical office building
B. Personal devices with no network access
C. Printed documents unrelated to technology
D. Cloud data, applications, and resources

14 What is the main purpose of a Cloud Access Security Broker (CASB)?

Cloud Security and SOC Operations: CASBs Easy
A. To replace every identity provider
B. To monitor and control cloud service use
C. To disable all approved cloud applications
D. To manufacture cloud servers

15 Which capability is commonly associated with a CASB?

Cloud Security and SOC Operations: CASBs Easy
A. Printer ink management
B. Office temperature control
C. Physical cable installation
D. Cloud application visibility

16 What is the purpose of container sandboxing?

Cloud Security and SOC Operations: container sandboxing Easy
A. To connect all containers without controls
B. To remove the need for access management
C. To store passwords in publicly available files
D. To isolate containerized workloads

17 What does configuration drift mean in a cloud environment?

Cloud Security and SOC Operations: compliance validation and drift detection Easy
A. A system receives its first security policy
B. A configuration changes from its approved state
C. A user reads an approved cloud document
D. A server is physically moved to another room

18 What is the purpose of encryption keys?

Cloud Security and SOC Operations: data and key management for encryption Easy
A. To replace all backup procedures
B. To identify a building's location
C. To control encryption and decryption
D. To measure network bandwidth

19 What is a multicloud environment?

Cloud Security and SOC Operations: securing multicloud and hybrid cloud environments Easy
A. A single server with no network connection
B. A private network used only for printing
C. An environment using multiple cloud providers
D. A system that stores data only on paper

20 How can APIs support cloud security operations?

Cloud Security and SOC Operations: role of APIs in cloud security and SOC operations Easy
A. By enabling tools to exchange security data
B. By removing the need to authenticate requests
C. By preventing all software from communicating
D. By physically locking cloud data centers

21 A SOC must demonstrate that privileged account activity is reviewed every week. Which approach provides the strongest compliance evidence?

Compliance and Regulatory Considerations in SOC: introduction Medium
A. Ask administrators to report unusual activity voluntarily
B. Record the names of current privileged account holders
C. Retain access logs and documented weekly review records
D. Store the privileged access policy in a shared folder

22 An auditor finds that the SOC collects security logs but has no documented retention schedule. What is the most important compliance risk?

Compliance and Regulatory Considerations in SOC: introduction Medium
A. Endpoints may generate logs in different formats
B. Analysts may receive too many duplicate alerts
C. Required evidence may be deleted before an audit
D. Dashboards may display inconsistent severity colors

23 A multinational company discovers a breach affecting customers in several countries. What should the SOC do first to address differing notification requirements?

Compliance and Regulatory Considerations in SOC: regulatory challenges across geographies Medium
A. Notify only the regulator where headquarters is located
B. Apply the shortest notification deadline to every incident
C. Wait until every affected record has been fully analyzed
D. Map affected individuals and systems to applicable jurisdictions

24 A global SOC wants one incident-response process while countries impose different data-residency rules. Which design best addresses both needs?

Compliance and Regulatory Considerations in SOC: regulatory challenges across geographies Medium
A. Transfer regulated logs whenever an analyst requests access
B. Allow each regional team to use unrelated response procedures
C. Use regional data stores with centralized alert coordination
D. Centralize all raw logs in the headquarters region

25 A hospital employee accidentally sends a patient file to the wrong external recipient. Which fact is most important when assessing the breach impact?

Compliance and Regulatory Considerations in SOC: healthcare data breaches Medium
A. Whether the employee completed training during the year
B. Whether the hospital owns its email infrastructure
C. Whether the recipient used a personal email application
D. Whether the file contained identifiable health information

26 A healthcare SOC detects repeated access to patient records by an employee outside the employee's assigned department. What is the most appropriate initial response?

Compliance and Regulatory Considerations in SOC: healthcare data breaches Medium
A. Delete older access logs to isolate recent events
B. Notify every patient before confirming unauthorized access
C. Disable auditing until the investigation is completed
D. Preserve evidence and validate the employee's business need

27 A bank detects an unusual transfer initiated through a compromised employee account. Which SOC action best supports both containment and financial compliance?

Compliance and Regulatory Considerations in SOC: financial services data security Medium
A. Reimage every workstation used by finance employees
B. Suspend the account and preserve transaction evidence
C. Delay escalation until the monthly control review
D. Remove the transfer record from operational databases

28 A payment processor wants to reduce the systems included in an assessment of cardholder data controls. Which change is most effective?

Compliance and Regulatory Considerations in SOC: financial services data security Medium
A. Segment cardholder systems from the general network
B. Move all employee devices into one network zone
C. Increase the storage capacity of its SIEM platform
D. Replace annual assessments with monthly vulnerability scans

29 Malware is detected on a workstation that supports an electric utility's operational network. Immediate shutdown could disrupt service. What should guide the containment decision?

Compliance and Regulatory Considerations in SOC: energy and utility incident response Medium
A. The age of the malware detection signature
B. The preference of the workstation's regular operator
C. The need to preserve safety and operational continuity
D. The amount of storage available for forensic images

30 A tabletop exercise shows that SOC analysts cannot contact the legal team outside business hours. What is the best corrective action?

Compliance and Regulatory Considerations in SOC: continuous incident readiness assessments Medium
A. Schedule future security incidents during business hours
B. Allow each analyst to select an external legal adviser
C. Remove legal review from all incident-response procedures
D. Add an on-call legal contact to the escalation process

31 Which metric best measures whether repeated incident-readiness exercises are improving the SOC's response capability?

Compliance and Regulatory Considerations in SOC: continuous incident readiness assessments Medium
A. Reduction in time to detect and contain test incidents
B. Total volume of logs collected during each exercise
C. Number of policies stored in the document repository
D. Number of employees assigned to the security department

32 An organization must alert on unauthorized changes to critical financial records. Which SIEM configuration best supports this requirement?

Compliance and Regulatory Considerations in SOC: role of SIEM in achieving compliance Medium
A. A report listing all installed endpoint applications
B. A filter that suppresses events from financial servers
C. A dashboard showing the daily number of user logins
D. A correlation rule combining change and authorization logs

33 A SIEM report must serve as audit evidence that failed administrator logins are reviewed. Which feature is most important?

Compliance and Regulatory Considerations in SOC: role of SIEM in achieving compliance Medium
A. Custom dashboard colors for each login severity
B. Manual deletion of events after each investigation
C. Scheduled reports with timestamps and reviewer records
D. Automatic compression of all network packet captures

34 A cloud-hosted database is exposed because a customer configured public access. Which concept should the SOC use when assigning responsibility?

Cloud Security and SOC Operations: introduction Medium
A. Automatic transfer of responsibility to external auditors
B. Complete customer responsibility for physical infrastructure
C. Shared responsibility between the provider and customer
D. Complete provider responsibility for every security control

35 Employees are uploading sensitive files to unsanctioned cloud storage services. Which CASB capability most directly addresses this issue?

Cloud Security and SOC Operations: CASBs Medium
A. Replace all endpoint operating systems automatically
B. Generate encryption keys without controlling their use
C. Discover cloud usage and enforce data loss policies
D. Repair physical faults in cloud data centers

36 A SOC is concerned that a compromised container could access the host operating system. Which control most directly reduces this risk?

Cloud Security and SOC Operations: container sandboxing Medium
A. Place application logs in the container's writable layer
B. Run containers with minimal privileges and restricted system calls
C. Assign every container the host's administrator account
D. Share the host network namespace across all containers

37 An approved cloud template requires storage encryption, but an administrator later disables encryption manually. Which capability should detect this condition?

Cloud Security and SOC Operations: compliance validation and drift detection Medium
A. Manual classification of phishing messages
B. Annual review of software license usage
C. Periodic compression of application logs
D. Continuous configuration drift monitoring

38 A company encrypts cloud data but stores encryption keys in the same database as the ciphertext. What improvement best reduces the impact of a database compromise?

Cloud Security and SOC Operations: data and key management for encryption Medium
A. Manage keys separately in a controlled key service
B. Use one permanent key for every cloud workload
C. Duplicate the keys across all application databases
D. Include encryption keys in centralized application logs

39 A SOC receives identity alerts from two cloud providers and an on-premises directory. What is the best way to detect account abuse across these environments?

Cloud Security and SOC Operations: securing multicloud and hybrid cloud environments Medium
A. Apply one provider's native policy to every platform
B. Normalize identity events and correlate them centrally
C. Investigate each environment using unrelated user identifiers
D. Disable cloud logs to reduce the number of alerts

40 A SOC automation tool uses a cloud provider's API to isolate compromised virtual machines. Which control is most important for the API credentials?

Cloud Security and SOC Operations: role of APIs in cloud security and SOC operations Medium
A. Embed administrator credentials in the automation source code
B. Grant only required actions and rotate credentials regularly
C. Share one unrestricted credential with every SOC application
D. Disable API activity logging to improve response speed

41 A multinational organization discovers that its SOC playbooks classify an incident only by technical severity. Which change most directly improves compliance-oriented incident handling?

Compliance and Regulatory Considerations in SOC: introduction Hard
A. Add regulatory impact and data-subject scope to incident classification
B. Increase the number of analysts assigned to every critical alert
C. Replace technical severity with the number of affected endpoints
D. Require all incidents to receive the same notification deadline

42 A breach affects EU residents, customers in a U.S. state with a sector-specific privacy law, and employees in a country requiring local breach investigation. What is the most defensible SOC response?

Compliance and Regulatory Considerations in SOC: regulatory challenges across geographies Hard
A. Notify only the regulator where the SOC is physically located
B. Map affected data subjects to applicable jurisdictional obligations
C. Apply the strictest notification rule to every affected person
D. Delay notification until the full forensic investigation is complete

43 A cloud provider stores centralized SOC logs in one region, but several jurisdictions restrict certain personal data from leaving their territory. Which control best addresses the conflict?

Compliance and Regulatory Considerations in SOC: regulatory challenges across geographies Hard
A. Store unrestricted raw logs centrally and restrict analyst access
B. Encrypt all logs after transferring them to the central region
C. Disable logging for systems located in restricted jurisdictions
D. Use regional collection, minimization, and jurisdiction-aware retention

44 A healthcare SOC confirms that an attacker accessed an encrypted database containing patient records, but the encryption key was not exposed. Which assessment is most important before concluding that notification is unnecessary?

Compliance and Regulatory Considerations in SOC: healthcare data breaches Hard
A. Whether the database had been compressed before encryption
B. Whether the encryption method and key management meet the applicable safe-harbor criteria
C. Whether the database administrator had completed annual training
D. Whether the attacker used a commodity malware family

45 A hospital uses a managed service provider that can access protected health information during incident response. Which SOC design most reduces accountability ambiguity after a breach?

Compliance and Regulatory Considerations in SOC: healthcare data breaches Hard
A. Let the provider define all notification responsibilities
B. Prohibit the provider from retaining any operational evidence
C. Treat the provider as an internal employee for every regulatory purpose
D. Document contractual roles, escalation paths, evidence access, and reporting deadlines

46 A bank detects anomalous transfers from a privileged service account. Which evidence set provides the strongest basis for both containment and regulatory defensibility?

Compliance and Regulatory Considerations in SOC: financial services data security Hard
A. A screenshot of the account dashboard and a password reset record
B. Analyst notes describing the suspected attacker motivation
C. Firewall denies and the final transaction totals
D. Immutable identity, transaction, endpoint, and administrative audit records

47 A financial institution wants to reduce false positives without weakening monitoring for suspicious account activity. Which approach best preserves compliance evidence quality?

Compliance and Regulatory Considerations in SOC: financial services data security Hard
A. Tune detection using risk context while retaining source events and decision logs
B. Delete low-confidence events after analysts close the alert
C. Suppress alerts from trusted administrator networks
D. Use only the core banking platform because it is the authoritative system

48 During a suspected attack on an electric utility, IT indicators suggest ransomware while the operational technology network remains stable. What should the SOC prioritize initially?

Compliance and Regulatory Considerations in SOC: energy and utility incident response Hard
A. Disconnect all industrial assets from every communication network
B. Immediately reboot affected control-system devices
C. Preserve safe operations while isolating confirmed IT attack paths
D. Wait for complete attribution before taking containment action

49 An energy company cannot collect endpoint agents from safety-certified control devices. Which compensating monitoring strategy is most appropriate?

Compliance and Regulatory Considerations in SOC: energy and utility incident response Hard
A. Disable security monitoring on the surrounding corporate network
B. Rely exclusively on user reports from plant operators
C. Use passive network telemetry, jump-host logs, and process-state anomalies
D. Install untested agents during the next active production cycle

50 A readiness assessment shows that the SOC has documented playbooks, but analysts cannot retrieve current contact information or restore required evidence from backups. What conclusion is most accurate?

Compliance and Regulatory Considerations in SOC: continuous incident readiness assessments Hard
A. The SOC is ready because the playbooks satisfy documentation requirements
B. The SOC has procedural readiness but lacks operational and recovery readiness
C. The SOC is ready if the incident commander has prior experience
D. The SOC needs only a larger backup retention period

51 Which assessment result most strongly indicates that an incident response program is improving rather than merely generating more exercises?

Compliance and Regulatory Considerations in SOC: continuous incident readiness assessments Hard
A. More employees attended awareness sessions than in the prior year
B. Repeated exercise findings have owners, deadlines, and verified closure evidence
C. The number of tabletop exercises increased each quarter
D. The mean time to acknowledge every alert decreased

52 An auditor asks the SOC to prove that privileged access reviews were performed quarterly. Which SIEM capability provides the strongest support?

Compliance and Regulatory Considerations in SOC: role of SIEM in achieving compliance Hard
A. Correlation of access events with review records and immutable timestamps
B. A policy document requiring quarterly access reviews
C. A malware alert showing that no privileged account was compromised
D. A dashboard showing the current number of administrators

53 A SIEM normalizes timestamps from systems using different time zones, but several source devices have unreliable clocks. What is the most important compliance risk?

Compliance and Regulatory Considerations in SOC: role of SIEM in achieving compliance Hard
A. The source devices will automatically lose administrator privileges
B. Event ordering and notification timelines may become indefensible
C. The SIEM will consume more storage than forecast
D. Normalization will prevent analysts from using correlation rules

54 In a cloud environment, a production workload is rebuilt from an image after an incident, causing the original instance's volatile evidence to disappear. Which operating model best addresses this risk?

Cloud Security and SOC Operations: introduction Hard
A. Treat cloud instances as permanent evidence repositories
B. Disable autoscaling until every investigation is complete
C. Permit analysts to investigate only after the workload is terminated
D. Automate acquisition of relevant metadata, logs, snapshots, and identity context

55 A CASB identifies uploads of sensitive documents to an unsanctioned cloud application. Which response is least likely to create an availability problem while still reducing exposure?

Cloud Security and SOC Operations: CASBs Hard
A. Allow the upload because the CASB cannot inspect every file
B. Block every cloud application for all users
C. Delete the user's identity from the directory immediately
D. Apply user, device, content, and destination-aware policy enforcement

56 A container executes untrusted code and attempts to access the host through a kernel vulnerability. Which control most directly limits the impact of a successful container escape?

Cloud Security and SOC Operations: container sandboxing Hard
A. Increase the container's CPU limit
B. Add more labels to the container image repository
C. Use a sandbox with a hardened isolation boundary and minimal host privileges
D. Store application logs in a separate object bucket

57 A compliant infrastructure template is deployed, but a later manual change exposes a storage bucket publicly. Which detection design provides the earliest reliable signal?

Cloud Security and SOC Operations: compliance validation and drift detection Hard
A. Compare continuously observed resource state with approved configuration baselines
B. Review the bucket during the next annual compliance audit
C. Scan only the original infrastructure template
D. Rely on application logs to report every permission change

58 An organization encrypts regulated data with a cloud key-management service, but application administrators can both deploy workloads and retrieve key material. Which weakness remains?

Cloud Security and SOC Operations: data and key management for encryption Hard
A. Encryption cannot protect data stored in object storage
B. The separation of duties and key-access boundary are insufficient
C. Key rotation makes the encrypted data impossible to recover
D. Cloud-managed keys cannot support regulatory requirements

59 A company has identical security policies across two clouds, but one provider logs control-plane actions differently and the private data center uses another identity system. What is the strongest SOC approach?

Cloud Security and SOC Operations: securing multicloud and hybrid cloud environments Hard
A. Assume equivalent policy text produces equivalent security outcomes
B. Require every provider to expose identical native APIs before monitoring
C. Normalize provider-specific telemetry and correlate identities across trust domains
D. Monitor only the cloud with the highest number of workloads

60 A SOAR platform uses a cloud API to disable a compromised identity. The API token has broad permissions and no expiration. Which remediation most directly reduces automation risk?

Cloud Security and SOC Operations: role of APIs in cloud security and SOC operations Hard
A. Store the token in an analyst's local configuration file
B. Increase the polling frequency of the SOAR integration
C. Use narrowly scoped, short-lived credentials with audited approval controls
D. Disable API logging to prevent sensitive token exposure