Unit 5: Compliance and Cloud Security Operations - Subjective Questions

INT244 — Securing Computing Systems • Practice Questions with Detailed Answers

20 questions

1

Explain the importance of compliance and regulatory considerations in Security Operations Center (SOC) activities.

2

Discuss the major regulatory challenges faced by organizations operating across multiple geographical regions.

3

Describe how a SOC should manage and investigate a healthcare data breach.

4

Explain the principal data security and compliance requirements applicable to financial services organizations.

5

Analyze the key considerations for incident response in the energy and utility sector.

6

What are continuous incident readiness assessments? Explain their purpose and major activities.

7

Explain the role of a Security Information and Event Management (SIEM) system in achieving and demonstrating compliance.

8

Derive a practical compliance monitoring workflow that uses SOC processes and SIEM capabilities.

9

Explain the relationship between cloud security and SOC operations.

10

What is a Cloud Access Security Broker (CASB)? Describe its major functions in cloud security operations.

11

Compare agent-based and agentless CASB approaches, including their advantages and limitations.

12

Explain container sandboxing and discuss how it supports secure SOC operations.

13

Describe compliance validation and configuration drift detection in cloud environments.

14

Explain the principles of data and key management for encryption in cloud security operations.

15

Analyze the security challenges of securing multicloud and hybrid cloud environments and propose suitable controls.

16

Discuss the role of APIs in cloud security and SOC operations.

17

Distinguish between compliance, governance, and security operations in the context of a SOC.

18

Compare the shared responsibility model in cloud security with traditional on-premises security responsibility.

19

Design an incident response approach for a suspected cloud storage exposure involving sensitive customer data.

20

Explain how a SOC can support regulatory breach notification requirements.