C.To replace security testing with informal discussions
D.To permanently stop all network communication
Correct Answer: To check whether response capabilities remain effective
Explanation:
Continuous assessments help verify that people, processes, tools, and plans are ready for security incidents.
Incorrect! Try again.
10Which activity can help test an organization's incident readiness?
Compliance and Regulatory Considerations in SOC: continuous incident readiness assessments
Easy
A.Removing emergency contact information
B.Ignoring previously reported incidents
C.Conducting a tabletop exercise
D.Avoiding updates to response procedures
Correct Answer: Conducting a tabletop exercise
Explanation:
A tabletop exercise allows teams to practice responding to a simulated incident and identify weaknesses.
Incorrect! Try again.
11What does a SIEM system commonly do with security logs?
Compliance and Regulatory Considerations in SOC: role of SIEM in achieving compliance
Easy
A.Collects and analyzes logs
B.Physically repairs damaged servers
C.Creates employee identity documents
D.Replaces all network devices
Correct Answer: Collects and analyzes logs
Explanation:
A SIEM collects security events from multiple sources and analyzes them to support monitoring, detection, and reporting.
Incorrect! Try again.
12How can a SIEM support compliance audits?
Compliance and Regulatory Considerations in SOC: role of SIEM in achieving compliance
Easy
A.By storing only unverified events without timestamps
B.By preventing every security incident
C.By providing searchable security records
D.By removing the need for written policies
Correct Answer: By providing searchable security records
Explanation:
SIEM records can help demonstrate monitoring activities, investigate events, and provide evidence during audits.
Incorrect! Try again.
13What is cloud security primarily concerned with protecting?
Cloud Security and SOC Operations: introduction
Easy
A.Only the physical office building
B.Personal devices with no network access
C.Printed documents unrelated to technology
D.Cloud data, applications, and resources
Correct Answer: Cloud data, applications, and resources
Explanation:
Cloud security protects information, applications, identities, workloads, and other resources hosted or managed in cloud environments.
Incorrect! Try again.
14What is the main purpose of a Cloud Access Security Broker (CASB)?
Cloud Security and SOC Operations: CASBs
Easy
A.To replace every identity provider
B.To monitor and control cloud service use
C.To disable all approved cloud applications
D.To manufacture cloud servers
Correct Answer: To monitor and control cloud service use
Explanation:
A CASB helps organizations apply security policies, monitor cloud activity, and protect data used with cloud services.
Incorrect! Try again.
15Which capability is commonly associated with a CASB?
Cloud Security and SOC Operations: CASBs
Easy
A.Printer ink management
B.Office temperature control
C.Physical cable installation
D.Cloud application visibility
Correct Answer: Cloud application visibility
Explanation:
CASBs can help organizations discover and monitor which cloud applications are being used.
Incorrect! Try again.
16What is the purpose of container sandboxing?
Cloud Security and SOC Operations: container sandboxing
Easy
A.To connect all containers without controls
B.To remove the need for access management
C.To store passwords in publicly available files
D.To isolate containerized workloads
Correct Answer: To isolate containerized workloads
Explanation:
Sandboxing limits how a container interacts with the host system and other workloads, reducing the impact of compromise.
Incorrect! Try again.
17What does configuration drift mean in a cloud environment?
Cloud Security and SOC Operations: compliance validation and drift detection
Easy
A.A system receives its first security policy
B.A configuration changes from its approved state
C.A user reads an approved cloud document
D.A server is physically moved to another room
Correct Answer: A configuration changes from its approved state
Explanation:
Configuration drift occurs when cloud settings gradually differ from the secure or compliant baseline.
Incorrect! Try again.
18What is the purpose of encryption keys?
Cloud Security and SOC Operations: data and key management for encryption
Easy
A.To replace all backup procedures
B.To identify a building's location
C.To control encryption and decryption
D.To measure network bandwidth
Correct Answer: To control encryption and decryption
Explanation:
Encryption keys are used to transform protected data and, when authorized, convert it back into readable form.
Incorrect! Try again.
19What is a multicloud environment?
Cloud Security and SOC Operations: securing multicloud and hybrid cloud environments
Easy
A.A single server with no network connection
B.A private network used only for printing
C.An environment using multiple cloud providers
D.A system that stores data only on paper
Correct Answer: An environment using multiple cloud providers
Explanation:
Multicloud environments use services from two or more cloud providers.
Incorrect! Try again.
20How can APIs support cloud security operations?
Cloud Security and SOC Operations: role of APIs in cloud security and SOC operations
Easy
A.By enabling tools to exchange security data
B.By removing the need to authenticate requests
C.By preventing all software from communicating
D.By physically locking cloud data centers
Correct Answer: By enabling tools to exchange security data
Explanation:
APIs allow security tools and cloud services to share information, retrieve events, and perform authorized actions.
Incorrect! Try again.
21A SOC must demonstrate that privileged account activity is reviewed every week. Which approach provides the strongest compliance evidence?
Compliance and Regulatory Considerations in SOC: introduction
Medium
A.Ask administrators to report unusual activity voluntarily
B.Record the names of current privileged account holders
C.Retain access logs and documented weekly review records
D.Store the privileged access policy in a shared folder
Correct Answer: Retain access logs and documented weekly review records
Explanation:
Compliance requires evidence that a control operates as intended. Logs combined with documented reviews demonstrate both activity and control execution.
Incorrect! Try again.
22An auditor finds that the SOC collects security logs but has no documented retention schedule. What is the most important compliance risk?
Compliance and Regulatory Considerations in SOC: introduction
Medium
A.Endpoints may generate logs in different formats
B.Analysts may receive too many duplicate alerts
C.Required evidence may be deleted before an audit
D.Dashboards may display inconsistent severity colors
Correct Answer: Required evidence may be deleted before an audit
Explanation:
A retention schedule ensures that required records remain available for investigations, audits, and regulatory reporting periods.
Incorrect! Try again.
23A multinational company discovers a breach affecting customers in several countries. What should the SOC do first to address differing notification requirements?
Compliance and Regulatory Considerations in SOC: regulatory challenges across geographies
Medium
A.Notify only the regulator where headquarters is located
B.Apply the shortest notification deadline to every incident
C.Wait until every affected record has been fully analyzed
D.Map affected individuals and systems to applicable jurisdictions
Correct Answer: Map affected individuals and systems to applicable jurisdictions
Explanation:
Identifying where affected individuals and systems are located allows legal and security teams to determine which laws, deadlines, and regulators apply.
Incorrect! Try again.
24A global SOC wants one incident-response process while countries impose different data-residency rules. Which design best addresses both needs?
Compliance and Regulatory Considerations in SOC: regulatory challenges across geographies
Medium
A.Transfer regulated logs whenever an analyst requests access
B.Allow each regional team to use unrelated response procedures
C.Use regional data stores with centralized alert coordination
D.Centralize all raw logs in the headquarters region
Correct Answer: Use regional data stores with centralized alert coordination
Explanation:
Regional storage can satisfy residency restrictions while centralized alert coordination supports consistent detection and response across the organization.
Incorrect! Try again.
25A hospital employee accidentally sends a patient file to the wrong external recipient. Which fact is most important when assessing the breach impact?
Compliance and Regulatory Considerations in SOC: healthcare data breaches
Medium
A.Whether the employee completed training during the year
B.Whether the hospital owns its email infrastructure
C.Whether the recipient used a personal email application
D.Whether the file contained identifiable health information
Correct Answer: Whether the file contained identifiable health information
Explanation:
The presence of identifiable health information is central to determining whether protected healthcare data was exposed and whether breach obligations apply.
Incorrect! Try again.
26A healthcare SOC detects repeated access to patient records by an employee outside the employee's assigned department. What is the most appropriate initial response?
Compliance and Regulatory Considerations in SOC: healthcare data breaches
Medium
A.Delete older access logs to isolate recent events
B.Notify every patient before confirming unauthorized access
C.Disable auditing until the investigation is completed
D.Preserve evidence and validate the employee's business need
Correct Answer: Preserve evidence and validate the employee's business need
Explanation:
The SOC should preserve relevant logs and determine whether the access was authorized before deciding on containment and notification actions.
Incorrect! Try again.
27A bank detects an unusual transfer initiated through a compromised employee account. Which SOC action best supports both containment and financial compliance?
Compliance and Regulatory Considerations in SOC: financial services data security
Medium
A.Reimage every workstation used by finance employees
B.Suspend the account and preserve transaction evidence
C.Delay escalation until the monthly control review
D.Remove the transfer record from operational databases
Correct Answer: Suspend the account and preserve transaction evidence
Explanation:
Suspending the compromised account limits further misuse, while preserving transaction and authentication records supports investigation and regulatory evidence requirements.
Incorrect! Try again.
28A payment processor wants to reduce the systems included in an assessment of cardholder data controls. Which change is most effective?
Compliance and Regulatory Considerations in SOC: financial services data security
Medium
A.Segment cardholder systems from the general network
B.Move all employee devices into one network zone
C.Increase the storage capacity of its SIEM platform
D.Replace annual assessments with monthly vulnerability scans
Correct Answer: Segment cardholder systems from the general network
Explanation:
Effective network segmentation limits access paths and can reduce the number of systems within the cardholder data environment's compliance scope.
Incorrect! Try again.
29Malware is detected on a workstation that supports an electric utility's operational network. Immediate shutdown could disrupt service. What should guide the containment decision?
Compliance and Regulatory Considerations in SOC: energy and utility incident response
Medium
A.The age of the malware detection signature
B.The preference of the workstation's regular operator
C.The need to preserve safety and operational continuity
D.The amount of storage available for forensic images
Correct Answer: The need to preserve safety and operational continuity
Explanation:
In energy and utility environments, containment must account for physical safety, service reliability, and operational consequences as well as cybersecurity risk.
Incorrect! Try again.
30A tabletop exercise shows that SOC analysts cannot contact the legal team outside business hours. What is the best corrective action?
Compliance and Regulatory Considerations in SOC: continuous incident readiness assessments
Medium
A.Schedule future security incidents during business hours
B.Allow each analyst to select an external legal adviser
C.Remove legal review from all incident-response procedures
D.Add an on-call legal contact to the escalation process
Correct Answer: Add an on-call legal contact to the escalation process
Explanation:
An on-call contact closes the identified escalation gap and supports timely legal guidance for notification, evidence handling, and regulatory decisions.
Incorrect! Try again.
31Which metric best measures whether repeated incident-readiness exercises are improving the SOC's response capability?
Compliance and Regulatory Considerations in SOC: continuous incident readiness assessments
Medium
A.Reduction in time to detect and contain test incidents
B.Total volume of logs collected during each exercise
C.Number of policies stored in the document repository
D.Number of employees assigned to the security department
Correct Answer: Reduction in time to detect and contain test incidents
Explanation:
Detection and containment times directly measure operational response performance and can be compared across exercises to identify improvement.
Incorrect! Try again.
32An organization must alert on unauthorized changes to critical financial records. Which SIEM configuration best supports this requirement?
Compliance and Regulatory Considerations in SOC: role of SIEM in achieving compliance
Medium
A.A report listing all installed endpoint applications
B.A filter that suppresses events from financial servers
C.A dashboard showing the daily number of user logins
D.A correlation rule combining change and authorization logs
Correct Answer: A correlation rule combining change and authorization logs
Explanation:
Correlating record changes with authorization data allows the SIEM to identify changes that lack a valid approval or authorized identity.
Incorrect! Try again.
33A SIEM report must serve as audit evidence that failed administrator logins are reviewed. Which feature is most important?
Compliance and Regulatory Considerations in SOC: role of SIEM in achieving compliance
Medium
A.Custom dashboard colors for each login severity
B.Manual deletion of events after each investigation
C.Scheduled reports with timestamps and reviewer records
D.Automatic compression of all network packet captures
Correct Answer: Scheduled reports with timestamps and reviewer records
Explanation:
Timestamped reports and reviewer records demonstrate that monitoring occurred consistently and that responsible personnel completed the required review.
Incorrect! Try again.
34A cloud-hosted database is exposed because a customer configured public access. Which concept should the SOC use when assigning responsibility?
Cloud Security and SOC Operations: introduction
Medium
A.Automatic transfer of responsibility to external auditors
B.Complete customer responsibility for physical infrastructure
C.Shared responsibility between the provider and customer
D.Complete provider responsibility for every security control
Correct Answer: Shared responsibility between the provider and customer
Explanation:
The shared responsibility model distinguishes provider duties, such as physical infrastructure, from customer duties, such as access and service configuration.
Incorrect! Try again.
35Employees are uploading sensitive files to unsanctioned cloud storage services. Which CASB capability most directly addresses this issue?
Cloud Security and SOC Operations: CASBs
Medium
A.Replace all endpoint operating systems automatically
B.Generate encryption keys without controlling their use
C.Discover cloud usage and enforce data loss policies
D.Repair physical faults in cloud data centers
Correct Answer: Discover cloud usage and enforce data loss policies
Explanation:
A CASB can identify shadow IT and apply data loss prevention controls to restrict sensitive uploads to unapproved cloud services.
Incorrect! Try again.
36A SOC is concerned that a compromised container could access the host operating system. Which control most directly reduces this risk?
Cloud Security and SOC Operations: container sandboxing
Medium
A.Place application logs in the container's writable layer
B.Run containers with minimal privileges and restricted system calls
C.Assign every container the host's administrator account
D.Share the host network namespace across all containers
Correct Answer: Run containers with minimal privileges and restricted system calls
Explanation:
Least privilege and system-call filtering reduce the operations available to a compromised container and make host escape more difficult.
Incorrect! Try again.
37An approved cloud template requires storage encryption, but an administrator later disables encryption manually. Which capability should detect this condition?
Cloud Security and SOC Operations: compliance validation and drift detection
Medium
Drift monitoring compares the current cloud configuration with the approved baseline and identifies unauthorized or noncompliant changes.
Incorrect! Try again.
38A company encrypts cloud data but stores encryption keys in the same database as the ciphertext. What improvement best reduces the impact of a database compromise?
Cloud Security and SOC Operations: data and key management for encryption
Medium
A.Manage keys separately in a controlled key service
B.Use one permanent key for every cloud workload
C.Duplicate the keys across all application databases
D.Include encryption keys in centralized application logs
Correct Answer: Manage keys separately in a controlled key service
Explanation:
Separating keys from encrypted data and controlling them through a key management service reduces the chance that one compromise exposes both.
Incorrect! Try again.
39A SOC receives identity alerts from two cloud providers and an on-premises directory. What is the best way to detect account abuse across these environments?
Cloud Security and SOC Operations: securing multicloud and hybrid cloud environments
Medium
A.Apply one provider's native policy to every platform
B.Normalize identity events and correlate them centrally
C.Investigate each environment using unrelated user identifiers
D.Disable cloud logs to reduce the number of alerts
Correct Answer: Normalize identity events and correlate them centrally
Explanation:
Normalization and centralized correlation let the SOC connect related identity activity across cloud and on-premises systems despite different log formats.
Incorrect! Try again.
40A SOC automation tool uses a cloud provider's API to isolate compromised virtual machines. Which control is most important for the API credentials?
Cloud Security and SOC Operations: role of APIs in cloud security and SOC operations
Medium
A.Embed administrator credentials in the automation source code
B.Grant only required actions and rotate credentials regularly
C.Share one unrestricted credential with every SOC application
D.Disable API activity logging to improve response speed
Correct Answer: Grant only required actions and rotate credentials regularly
Explanation:
Least-privilege permissions and credential rotation limit the damage caused by API credential theft while retaining the actions required for response.
Incorrect! Try again.
41A multinational organization discovers that its SOC playbooks classify an incident only by technical severity. Which change most directly improves compliance-oriented incident handling?
Compliance and Regulatory Considerations in SOC: introduction
Hard
A.Add regulatory impact and data-subject scope to incident classification
B.Increase the number of analysts assigned to every critical alert
C.Replace technical severity with the number of affected endpoints
D.Require all incidents to receive the same notification deadline
Correct Answer: Add regulatory impact and data-subject scope to incident classification
Explanation:
Compliance obligations depend on factors such as affected data, individuals, jurisdiction, and notification thresholds, not only technical severity.
Incorrect! Try again.
42A breach affects EU residents, customers in a U.S. state with a sector-specific privacy law, and employees in a country requiring local breach investigation. What is the most defensible SOC response?
Compliance and Regulatory Considerations in SOC: regulatory challenges across geographies
Hard
A.Notify only the regulator where the SOC is physically located
B.Map affected data subjects to applicable jurisdictional obligations
C.Apply the strictest notification rule to every affected person
D.Delay notification until the full forensic investigation is complete
Correct Answer: Map affected data subjects to applicable jurisdictional obligations
Explanation:
Jurisdictional duties attach to affected people, data, processing activities, and local requirements; a single global rule may be insufficient or unnecessarily broad.
Incorrect! Try again.
43A cloud provider stores centralized SOC logs in one region, but several jurisdictions restrict certain personal data from leaving their territory. Which control best addresses the conflict?
Compliance and Regulatory Considerations in SOC: regulatory challenges across geographies
Hard
A.Store unrestricted raw logs centrally and restrict analyst access
B.Encrypt all logs after transferring them to the central region
C.Disable logging for systems located in restricted jurisdictions
D.Use regional collection, minimization, and jurisdiction-aware retention
Correct Answer: Use regional collection, minimization, and jurisdiction-aware retention
Explanation:
Encryption and access control do not necessarily resolve data-residency restrictions. Regional processing and minimization reduce prohibited transfers while preserving monitoring.
Incorrect! Try again.
44A healthcare SOC confirms that an attacker accessed an encrypted database containing patient records, but the encryption key was not exposed. Which assessment is most important before concluding that notification is unnecessary?
Compliance and Regulatory Considerations in SOC: healthcare data breaches
Hard
A.Whether the database had been compressed before encryption
B.Whether the encryption method and key management meet the applicable safe-harbor criteria
C.Whether the database administrator had completed annual training
D.Whether the attacker used a commodity malware family
Correct Answer: Whether the encryption method and key management meet the applicable safe-harbor criteria
Explanation:
Breach exceptions often depend on approved encryption and proper key protection. Encryption alone is not enough if implementation or key management is inadequate.
Incorrect! Try again.
45A hospital uses a managed service provider that can access protected health information during incident response. Which SOC design most reduces accountability ambiguity after a breach?
Compliance and Regulatory Considerations in SOC: healthcare data breaches
Hard
A.Let the provider define all notification responsibilities
B.Prohibit the provider from retaining any operational evidence
C.Treat the provider as an internal employee for every regulatory purpose
D.Document contractual roles, escalation paths, evidence access, and reporting deadlines
Clear agreements and operating procedures establish who investigates, preserves evidence, escalates, and reports when a third party handles protected data.
Incorrect! Try again.
46A bank detects anomalous transfers from a privileged service account. Which evidence set provides the strongest basis for both containment and regulatory defensibility?
Compliance and Regulatory Considerations in SOC: financial services data security
Hard
A.A screenshot of the account dashboard and a password reset record
B.Analyst notes describing the suspected attacker motivation
C.Firewall denies and the final transaction totals
D.Immutable identity, transaction, endpoint, and administrative audit records
Correct Answer: Immutable identity, transaction, endpoint, and administrative audit records
Explanation:
Financial investigations require attributable, time-correlated, tamper-evident evidence linking identity activity, system actions, and financial transactions.
Incorrect! Try again.
47A financial institution wants to reduce false positives without weakening monitoring for suspicious account activity. Which approach best preserves compliance evidence quality?
Compliance and Regulatory Considerations in SOC: financial services data security
Hard
A.Tune detection using risk context while retaining source events and decision logs
B.Delete low-confidence events after analysts close the alert
C.Suppress alerts from trusted administrator networks
D.Use only the core banking platform because it is the authoritative system
Correct Answer: Tune detection using risk context while retaining source events and decision logs
Explanation:
Risk-based tuning improves signal quality, while retaining raw evidence and detection decisions supports auditability and later investigation.
Incorrect! Try again.
48During a suspected attack on an electric utility, IT indicators suggest ransomware while the operational technology network remains stable. What should the SOC prioritize initially?
Compliance and Regulatory Considerations in SOC: energy and utility incident response
Hard
A.Disconnect all industrial assets from every communication network
C.Preserve safe operations while isolating confirmed IT attack paths
D.Wait for complete attribution before taking containment action
Correct Answer: Preserve safe operations while isolating confirmed IT attack paths
Explanation:
Utility response must balance cybersecurity containment with safety and availability. Uncoordinated OT actions can create operational hazards.
Incorrect! Try again.
49An energy company cannot collect endpoint agents from safety-certified control devices. Which compensating monitoring strategy is most appropriate?
Compliance and Regulatory Considerations in SOC: energy and utility incident response
Hard
A.Disable security monitoring on the surrounding corporate network
B.Rely exclusively on user reports from plant operators
C.Use passive network telemetry, jump-host logs, and process-state anomalies
D.Install untested agents during the next active production cycle
Correct Answer: Use passive network telemetry, jump-host logs, and process-state anomalies
Explanation:
Passive monitoring and intermediary access logs provide visibility without risking unsupported changes to safety-critical systems.
Incorrect! Try again.
50A readiness assessment shows that the SOC has documented playbooks, but analysts cannot retrieve current contact information or restore required evidence from backups. What conclusion is most accurate?
Compliance and Regulatory Considerations in SOC: continuous incident readiness assessments
Hard
A.The SOC is ready because the playbooks satisfy documentation requirements
B.The SOC has procedural readiness but lacks operational and recovery readiness
C.The SOC is ready if the incident commander has prior experience
D.The SOC needs only a larger backup retention period
Correct Answer: The SOC has procedural readiness but lacks operational and recovery readiness
Explanation:
Readiness must be demonstrated through executable procedures, reachable participants, usable tooling, and recoverable evidence, not documentation alone.
Incorrect! Try again.
51Which assessment result most strongly indicates that an incident response program is improving rather than merely generating more exercises?
Compliance and Regulatory Considerations in SOC: continuous incident readiness assessments
Hard
A.More employees attended awareness sessions than in the prior year
B.Repeated exercise findings have owners, deadlines, and verified closure evidence
C.The number of tabletop exercises increased each quarter
D.The mean time to acknowledge every alert decreased
Correct Answer: Repeated exercise findings have owners, deadlines, and verified closure evidence
Explanation:
Improvement is demonstrated when findings lead to tracked corrective actions whose effectiveness is independently validated.
Incorrect! Try again.
52An auditor asks the SOC to prove that privileged access reviews were performed quarterly. Which SIEM capability provides the strongest support?
Compliance and Regulatory Considerations in SOC: role of SIEM in achieving compliance
Hard
A.Correlation of access events with review records and immutable timestamps
C.A malware alert showing that no privileged account was compromised
D.A dashboard showing the current number of administrators
Correct Answer: Correlation of access events with review records and immutable timestamps
Explanation:
Compliance evidence must show what access existed, what was reviewed, when it was reviewed, and how the records were protected from alteration.
Incorrect! Try again.
53A SIEM normalizes timestamps from systems using different time zones, but several source devices have unreliable clocks. What is the most important compliance risk?
Compliance and Regulatory Considerations in SOC: role of SIEM in achieving compliance
Hard
A.The source devices will automatically lose administrator privileges
B.Event ordering and notification timelines may become indefensible
C.The SIEM will consume more storage than forecast
D.Normalization will prevent analysts from using correlation rules
Correct Answer: Event ordering and notification timelines may become indefensible
Explanation:
Unreliable clocks undermine chronology, incident reconstruction, service-level measurements, and proof that regulatory deadlines were met.
Incorrect! Try again.
54In a cloud environment, a production workload is rebuilt from an image after an incident, causing the original instance's volatile evidence to disappear. Which operating model best addresses this risk?
Cloud Security and SOC Operations: introduction
Hard
A.Treat cloud instances as permanent evidence repositories
B.Disable autoscaling until every investigation is complete
C.Permit analysts to investigate only after the workload is terminated
D.Automate acquisition of relevant metadata, logs, snapshots, and identity context
Correct Answer: Automate acquisition of relevant metadata, logs, snapshots, and identity context
Explanation:
Cloud resources are ephemeral. Evidence collection must be integrated into response workflows before replacement or termination removes useful state.
Incorrect! Try again.
55A CASB identifies uploads of sensitive documents to an unsanctioned cloud application. Which response is least likely to create an availability problem while still reducing exposure?
Cloud Security and SOC Operations: CASBs
Hard
A.Allow the upload because the CASB cannot inspect every file
B.Block every cloud application for all users
C.Delete the user's identity from the directory immediately
D.Apply user, device, content, and destination-aware policy enforcement
Correct Answer: Apply user, device, content, and destination-aware policy enforcement
Explanation:
Context-aware CASB controls can block or quarantine risky transfers while preserving legitimate cloud use and avoiding excessive disruption.
Incorrect! Try again.
56A container executes untrusted code and attempts to access the host through a kernel vulnerability. Which control most directly limits the impact of a successful container escape?
Cloud Security and SOC Operations: container sandboxing
Hard
A.Increase the container's CPU limit
B.Add more labels to the container image repository
C.Use a sandbox with a hardened isolation boundary and minimal host privileges
D.Store application logs in a separate object bucket
Correct Answer: Use a sandbox with a hardened isolation boundary and minimal host privileges
Explanation:
Sandboxing, reduced privileges, and a strong isolation boundary limit host access if the application or container runtime is compromised.
Incorrect! Try again.
57A compliant infrastructure template is deployed, but a later manual change exposes a storage bucket publicly. Which detection design provides the earliest reliable signal?
Cloud Security and SOC Operations: compliance validation and drift detection
Hard
A.Compare continuously observed resource state with approved configuration baselines
B.Review the bucket during the next annual compliance audit
C.Scan only the original infrastructure template
D.Rely on application logs to report every permission change
Correct Answer: Compare continuously observed resource state with approved configuration baselines
Explanation:
Drift detection evaluates actual deployed state, so it can identify unauthorized changes that template validation cannot see after deployment.
Incorrect! Try again.
58An organization encrypts regulated data with a cloud key-management service, but application administrators can both deploy workloads and retrieve key material. Which weakness remains?
Cloud Security and SOC Operations: data and key management for encryption
Hard
A.Encryption cannot protect data stored in object storage
B.The separation of duties and key-access boundary are insufficient
C.Key rotation makes the encrypted data impossible to recover
D.Cloud-managed keys cannot support regulatory requirements
Correct Answer: The separation of duties and key-access boundary are insufficient
Explanation:
Encryption effectiveness depends on access governance. Administrators who can deploy workloads and obtain key material may bypass the intended protection.
Incorrect! Try again.
59A company has identical security policies across two clouds, but one provider logs control-plane actions differently and the private data center uses another identity system. What is the strongest SOC approach?
Cloud Security and SOC Operations: securing multicloud and hybrid cloud environments
Hard
A.Assume equivalent policy text produces equivalent security outcomes
B.Require every provider to expose identical native APIs before monitoring
C.Normalize provider-specific telemetry and correlate identities across trust domains
D.Monitor only the cloud with the highest number of workloads
Correct Answer: Normalize provider-specific telemetry and correlate identities across trust domains
Explanation:
Multicloud visibility requires translating different event schemas and associating identities across cloud, on-premises, and federated systems.
Incorrect! Try again.
60A SOAR platform uses a cloud API to disable a compromised identity. The API token has broad permissions and no expiration. Which remediation most directly reduces automation risk?
Cloud Security and SOC Operations: role of APIs in cloud security and SOC operations
Hard
A.Store the token in an analyst's local configuration file
B.Increase the polling frequency of the SOAR integration
C.Use narrowly scoped, short-lived credentials with audited approval controls
D.Disable API logging to prevent sensitive token exposure
Correct Answer: Use narrowly scoped, short-lived credentials with audited approval controls
Explanation:
Least privilege, short credential lifetimes, and auditable approvals limit the damage from a stolen integration token or erroneous automated action.
Incorrect! Try again.
Did this save you a night before the exam?
LPU Notes is free, and it stays free. Ads cover part of the server bill.
The rest comes out of a student's own pocket: the domain, the storage,
and keeping the site up through the weeks everyone needs it at once.
The payment button didn't load. An ad blocker or a filtered network is the usual reason.
to try again.
Nothing here is ever locked, and nothing unlocks. Chip in only if it was worth it.
What it pays for →