Regular audits help confirm whether cloud systems follow required security policies and regulations.
Incorrect! Try again.
13What is the main function of Identity and Access Management (IAM)?
Identity and Access Management (IAM)
Easy
A.Increasing wireless signal strength
B.Cooling physical server rooms
C.Controlling access to resources
D.Compressing files before upload
Correct Answer: Controlling access to resources
Explanation:
IAM verifies identities and controls which cloud resources each identity is allowed to access.
Incorrect! Try again.
14Which IAM process confirms that a user is who they claim to be?
Identity and Access Management (IAM)
Easy
A.Authorization
B.Accounting
C.Authentication
D.Archiving
Correct Answer: Authentication
Explanation:
Authentication verifies a user's identity, while authorization determines what the verified user can access.
Incorrect! Try again.
15In Azure Active Directory, what is a tenant?
Azure Active Directory (AAD) structure
Easy
A.A physical storage device
B.A software testing method
C.A dedicated identity directory
D.A network routing protocol
Correct Answer: A dedicated identity directory
Explanation:
An Azure AD tenant is a dedicated directory instance that contains an organization's identities and access settings.
Incorrect! Try again.
16Which item is commonly stored in an Azure Active Directory tenant?
Azure Active Directory (AAD) structure
Easy
A.User identity
B.Processor temperature
C.Monitor resolution
D.Printer ink level
Correct Answer: User identity
Explanation:
An Azure AD tenant stores identity objects such as users, groups, applications, and devices.
Incorrect! Try again.
17Why are users placed into groups in a cloud directory?
User and group management
Easy
A.To increase account password length
B.To manage permissions collectively
C.To change file storage formats
D.To reduce network cable usage
Correct Answer: To manage permissions collectively
Explanation:
Groups make it easier to assign the same permissions and policies to multiple users.
Incorrect! Try again.
18What should an administrator do when an employee permanently leaves an organization?
User and group management
Easy
A.Disable the employee's account
B.Share the employee's password
C.Increase the employee's permissions
D.Move the account to a public group
Correct Answer: Disable the employee's account
Explanation:
Disabling the account prevents the former employee from accessing organizational cloud resources.
Incorrect! Try again.
19What does Multi-Factor Authentication (MFA) require?
Multi-Factor Authentication (MFA)
Easy
A.Two or more usernames
B.Two or more email addresses
C.Two or more cloud providers
D.Two or more verification factors
Correct Answer: Two or more verification factors
Explanation:
MFA requires multiple forms of verification, such as a password and a code sent to a trusted device.
Incorrect! Try again.
20A user receives an unexpected MFA approval request without trying to sign in. What should the user do?
Real-time scenario-based case studies
Easy
A.Deny the request and report it
B.Approve the request immediately
C.Forward the request to coworkers
D.Disable all device notifications
Correct Answer: Deny the request and report it
Explanation:
An unexpected MFA request may indicate a stolen password or an attempted account compromise.
Incorrect! Try again.
21An organization stores sensitive customer records in cloud object storage. Which combination of controls best protects the records against unauthorized disclosure?
Overview of cloud security and methods
Medium
A.Data compression, replication, and load balancing
B.Auto-scaling, caching, and resource tagging
C.Encryption, least-privilege access, and activity logging
D.Version control, orchestration, and traffic shaping
Correct Answer: Encryption, least-privilege access, and activity logging
Explanation:
Encryption protects data, least privilege limits access, and logging helps detect and investigate unauthorized activity.
Incorrect! Try again.
22A cloud administrator wants to identify virtual machines that are missing security patches. Which cloud security method is most appropriate?
Continuous vulnerability assessment detects missing patches, insecure software versions, and known weaknesses in cloud workloads.
Incorrect! Try again.
23A company runs an application on an Infrastructure as a Service (IaaS) virtual machine. Who is normally responsible for patching the guest operating system?
Shared responsibility model of cloud security
Medium
A.The hardware manufacturer
B.The customer organization
C.The network carrier alone
D.The cloud provider alone
Correct Answer: The customer organization
Explanation:
In IaaS, the provider secures the physical infrastructure and virtualization layer, while the customer manages the guest operating system and applications.
Incorrect! Try again.
24A software company uses a managed Platform as a Service (PaaS) database. Which task is generally the cloud provider's responsibility?
Shared responsibility model of cloud security
Medium
A.Defining the organization's retention policy
B.Assigning roles to business analysts
C.Maintaining the underlying database platform
D.Classifying the company's customer data
Correct Answer: Maintaining the underlying database platform
Explanation:
In PaaS, the provider generally maintains the infrastructure, operating system, and managed platform, while the customer manages data and access.
Incorrect! Try again.
25A development team creates cloud storage for testing and accidentally allows anonymous internet access. Which common cloud security challenge does this illustrate?
Common cloud security challenges
Medium
A.Resource misconfiguration
B.Vendor lock-in
C.Capacity exhaustion
D.Network latency
Correct Answer: Resource misconfiguration
Explanation:
Incorrect access settings are a cloud misconfiguration and can expose data or services to unauthorized users.
Incorrect! Try again.
26An organization uses services from three cloud providers but cannot consistently monitor security events across them. Which action best addresses this challenge?
Common cloud security challenges
Medium
A.Increase storage capacity in every cloud
B.Centralize logs in a security monitoring platform
C.Disable alerts generated by individual services
D.Move all workloads to public IP addresses
Correct Answer: Centralize logs in a security monitoring platform
Explanation:
Centralized logging and monitoring improve visibility by correlating security events from multiple cloud environments.
Incorrect! Try again.
27A storage access key is accidentally published in a public code repository. What should the security team do first?
Data breaches
Medium
A.Increase the storage replication level
B.Rotate or revoke the exposed key
C.Archive the repository for future review
D.Rename the affected storage account
Correct Answer: Rotate or revoke the exposed key
Explanation:
Revoking or rotating the exposed credential immediately prevents attackers from continuing to use it.
Incorrect! Try again.
28After detecting unusual downloads from a cloud database, which evidence would be most useful for determining which identity accessed the records?
Data breaches
Medium
A.Resource pricing reports
B.Application design diagrams
C.Authentication and audit logs
D.Storage capacity metrics
Correct Answer: Authentication and audit logs
Explanation:
Authentication and audit logs record sign-ins, identities, operations, timestamps, and other details needed for breach investigation.
Incorrect! Try again.
29A database administrator can both approve and execute the export of sensitive customer data. Which control would best reduce the insider threat?
Insider threats
Medium
A.Automatic load balancing
B.Storage lifecycle management
C.Geographic replication
D.Separation of duties
Correct Answer: Separation of duties
Explanation:
Separation of duties prevents one person from controlling every stage of a sensitive operation.
Incorrect! Try again.
30An employee who is leaving the company begins downloading unusually large amounts of confidential data. Which control would most directly help detect and stop this behavior?
Insider threats
Medium
A.A data loss prevention policy
B.A database indexing policy
C.A content delivery network
D.A virtual machine scale set
Correct Answer: A data loss prevention policy
Explanation:
Data loss prevention can detect sensitive information leaving approved locations and block or alert on suspicious transfers.
Incorrect! Try again.
31A regulation requires personal data to remain within a specific country. Which cloud design decision most directly supports this requirement?
Compliance risks
Medium
A.Increasing the number of user accounts
B.Enabling automatic application scaling
C.Selecting an approved deployment region
D.Using larger virtual machine instances
Correct Answer: Selecting an approved deployment region
Explanation:
Choosing an approved region helps satisfy data residency requirements by controlling where regulated data is stored and processed.
Incorrect! Try again.
32An auditor asks the organization to prove that administrative actions are recorded and retained for one year. Which configuration best meets this requirement?
Compliance risks
Medium
A.Enable encryption and rotate keys once each year
B.Enable audit logs and apply a one-year retention policy
C.Enable backups and retain only the latest copy
D.Enable auto-scaling and review usage each month
Correct Answer: Enable audit logs and apply a one-year retention policy
Explanation:
Audit logging records administrative actions, while the retention policy preserves the evidence for the required period.
Incorrect! Try again.
33A support engineer needs permission to restart virtual machines but must not create, delete, or resize them. Which IAM approach is most appropriate?
Identity and Access Management (IAM)
Medium
A.Assign the subscription owner role
B.Grant permanent global administrator access
C.Create a least-privilege custom role
D.Share an administrator account
Correct Answer: Create a least-privilege custom role
Explanation:
A custom role can grant only the restart permission required for the engineer's duties.
Incorrect! Try again.
34A company wants employees to access several cloud applications by authenticating once with the corporate identity provider. Which IAM capability should it implement?
Identity and Access Management (IAM)
Medium
A.Network peering
B.Database replication
C.Single sign-on
D.Disk encryption
Correct Answer: Single sign-on
Explanation:
Single sign-on lets users authenticate through a trusted identity provider and then access multiple authorized applications.
Incorrect! Try again.
35A company has several Azure subscriptions that should use the same employee identities. Which arrangement supports this requirement?
Azure Active Directory (AAD) structure
Medium
A.Create local accounts on every Azure resource
B.Associate the subscriptions with one AAD tenant
C.Associate each user with a different subscription
D.Create a separate tenant for every virtual machine
Correct Answer: Associate the subscriptions with one AAD tenant
Explanation:
Multiple Azure subscriptions can trust the same Azure Active Directory tenant for centralized identity and access management.
Incorrect! Try again.
36A partner must access an application in the company's Azure Active Directory tenant while continuing to use the partner organization's credentials. Which feature is most suitable?
AAD B2B guest access allows external users to collaborate using identities managed by their home organizations.
Incorrect! Try again.
37All members of the Finance department need the same access to a reporting application. What is the most manageable approach?
User and group management
Medium
A.Grant access through public application links
B.Assign access to a Finance security group
C.Assign access separately to each user
D.Create one shared Finance user account
Correct Answer: Assign access to a Finance security group
Explanation:
Group-based assignment simplifies access management because permissions change automatically as users join or leave the group.
Incorrect! Try again.
38An AAD dynamic group should contain all active users whose department attribute is set to Sales. What is the main management benefit?
User and group management
Medium
A.Membership updates automatically from user attributes
B.Every member receives global administrator rights
C.Membership remains fixed after group creation
D.Users can bypass application authorization checks
Correct Answer: Membership updates automatically from user attributes
Explanation:
Dynamic groups evaluate membership rules and automatically add or remove users when relevant attributes change.
Incorrect! Try again.
39An attacker obtains an employee's cloud password through phishing. Why can MFA still prevent account access?
Multi-Factor Authentication (MFA)
Medium
A.It automatically deletes the stolen password
B.It blocks all access from external networks
C.It requires an additional verification factor
D.It hides the account's username from attackers
Correct Answer: It requires an additional verification factor
Explanation:
MFA requires another factor, such as an authenticator approval or security key, so a password alone is insufficient.
Incorrect! Try again.
40A remote administrator signs in from an unfamiliar country and attempts to modify production firewall rules. Which response best balances security and legitimate access?
Real-time scenario-based case studies
Medium
A.Allow the sign-in because the password is correct
B.Delete the administrator account immediately
C.Disable all production firewall protections
D.Require MFA and verify the sign-in risk
Correct Answer: Require MFA and verify the sign-in risk
Explanation:
Risk-based verification and MFA provide additional assurance before permitting a sensitive action from an unusual location.
Incorrect! Try again.
41An enterprise needs continuous detection of publicly exposed storage, overly permissive IAM policies, and configuration drift across hundreds of cloud subscriptions. Which security method most directly addresses this requirement?
Overview of cloud security and methods
Hard
A.Forward application events to a centralized security information system
B.Implement Cloud Security Posture Management across the subscriptions
C.Deploy a Cloud Access Security Broker to inspect user traffic
D.Install Cloud Workload Protection agents on all compute instances
Correct Answer: Implement Cloud Security Posture Management across the subscriptions
Explanation:
Cloud Security Posture Management continuously discovers cloud resources, identifies misconfigurations, evaluates compliance, and detects drift across accounts or subscriptions.
Incorrect! Try again.
42A company deploys an application on a managed Platform as a Service offering. A vulnerability is discovered in an application library packaged by the development team, while the underlying operating system is fully patched. Who is primarily responsible for remediating the library?
Shared responsibility model of cloud security
Hard
A.The provider, because it patches the platform operating system
B.The provider, because it operates the managed application platform
C.The customer, because it controls the application and its dependencies
D.The customer, because it owns the physical infrastructure configuration
Correct Answer: The customer, because it controls the application and its dependencies
Explanation:
In a PaaS model, the provider secures the underlying platform, but the customer remains responsible for application code, packaged dependencies, data, identities, and configuration.
Incorrect! Try again.
43A cloud environment creates and deletes serverless resources within minutes. A nightly scanner repeatedly misses vulnerable resources that existed long enough to process sensitive data. Which change best addresses this visibility gap?
Common cloud security challenges
Hard
A.Use event-driven discovery and policy enforcement during resource creation
B.Replace serverless resources with permanently running virtual machines
C.Increase the nightly scanner's vulnerability severity threshold
D.Retain application data longer so scanners can inspect it later
Correct Answer: Use event-driven discovery and policy enforcement during resource creation
Explanation:
Ephemeral resources may disappear before periodic scans occur. Event-driven controls evaluate resources when they are created or changed, reducing the visibility gap.
Incorrect! Try again.
44An attacker obtains a cloud administrator credential and attempts to erase evidence after downloading sensitive objects. Which preconfigured control would provide the strongest support for reconstructing the breach?
Data breaches
Hard
A.Export audit logs to immutable storage under a separate security account
B.Store administrative activity logs on each administrator's workstation
C.Enable detailed logging within the same compromised cloud subscription
D.Retain database transaction logs on the affected database server
Correct Answer: Export audit logs to immutable storage under a separate security account
Explanation:
Separating immutable logs from the administered environment prevents a compromised administrator from modifying or deleting the primary evidence.
Incorrect! Try again.
45A production administrator requires privileged access for occasional maintenance but must not approve their own requests. Access must expire automatically, and every activation must be auditable. Which design best satisfies these requirements?
Insider threats
Hard
A.Grant standing access but require a second factor during interactive login
B.Assign permanent access and review the administrator's activity quarterly
C.Use just-in-time privileged access with approval and time-bound activation
D.Share an administrative account whose password rotates after each session
Correct Answer: Use just-in-time privileged access with approval and time-bound activation
Explanation:
Just-in-time privileged access limits standing privilege, supports independent approval, records activation, and automatically removes access when the approved period ends.
Incorrect! Try again.
46A regulated workload must keep all customer records within one approved country. The primary database is correctly located, but automated backups are copied to a provider-managed recovery region abroad. Encryption is enabled. What is the principal compliance issue?
Compliance risks
Hard
A.Only the primary database matters because backups are not active records
B.Backup location may violate residency rules despite encryption at rest
C.Provider-managed recovery regions are automatically exempt from regulation
D.Encryption removes the residency risk because foreign backups are unreadable
Correct Answer: Backup location may violate residency rules despite encryption at rest
Explanation:
Data residency obligations may apply to backups, replicas, logs, and disaster-recovery copies. Encryption does not change the geographic location in which data is stored or processed.
Incorrect! Try again.
47An Azure user receives the Owner role at the subscription scope. A deny assignment at a child resource group prohibits deletion of virtual networks and applies to that user. What happens when the user attempts such a deletion in the resource group?
Identity and Access Management (IAM)
Hard
A.The deletion succeeds because a subscription-level role overrides child controls
B.The deletion is blocked only if the user also has a resource-group role
C.The deletion is blocked because the applicable deny assignment takes precedence
D.The deletion succeeds because the Owner role includes all management actions
Correct Answer: The deletion is blocked because the applicable deny assignment takes precedence
Explanation:
Azure evaluates applicable deny assignments after aggregating allowed actions. An inherited Owner role does not override an applicable deny assignment.
Incorrect! Try again.
48Which statement correctly describes the relationship between an Azure Active Directory tenant and Azure subscriptions?
Azure Active Directory (AAD) structure
Hard
A.Every subscription maintains an independent directory that cannot be changed
B.A tenant can be associated with only one subscription throughout its lifetime
C.A subscription can simultaneously trust several directories for authentication
D.One tenant can serve multiple subscriptions, while each subscription trusts one tenant
Correct Answer: One tenant can serve multiple subscriptions, while each subscription trusts one tenant
Explanation:
A single Azure AD tenant can provide identities for multiple subscriptions. At a given time, each Azure subscription has a trust relationship with one tenant.
Incorrect! Try again.
49A synchronized user's department attribute changes from Sales to Finance. Two minutes later, the user is still absent from an Azure AD dynamic group whose rule includes users with department equal to Finance. Audit records confirm that the new attribute is present. What is the most likely explanation?
User and group management
Hard
A.Department attributes can be used only with assigned security group membership
B.The user must sign out before the dynamic group rule can evaluate the attribute
C.Dynamic membership reevaluation is asynchronous and may not have completed
D.Dynamic groups cannot evaluate attributes synchronized from on-premises systems
Correct Answer: Dynamic membership reevaluation is asynchronous and may not have completed
Explanation:
Azure AD dynamic group processing is asynchronous. Even after an attribute is updated, membership changes may require additional processing time.
Incorrect! Try again.
50An organization enables MFA for all users, yet an attacker successfully authenticates to a mailbox using a stolen password through an older email protocol. Which control gap most plausibly enabled the attack?
Multi-Factor Authentication (MFA)
Hard
A.Password synchronization caused the second factor to be cached indefinitely
B.Legacy authentication was permitted even though it could not perform MFA
C.Group-based licensing prevented MFA from applying to cloud applications
D.Self-service password reset automatically exempted the mailbox from MFA
Correct Answer: Legacy authentication was permitted even though it could not perform MFA
Explanation:
Legacy authentication protocols generally cannot complete modern MFA challenges. Blocking legacy authentication is necessary to prevent this common bypass path.
Incorrect! Try again.
51A tenant-wide Conditional Access policy requires federated authentication and MFA for every administrator. During an outage of the external identity provider, no administrator can sign in. Which prior design would have provided the safest recovery path?
Real-time scenario-based case studies
Hard
A.Create a shared Global Administrator account protected by a rotating password
B.Maintain two monitored cloud-only emergency accounts excluded from the policy
C.Disable audit logging for one administrator to ensure uninterrupted access
D.Give every administrator a permanent password that bypasses federation failures
Correct Answer: Maintain two monitored cloud-only emergency accounts excluded from the policy
Explanation:
Cloud-only emergency access accounts reduce dependency on federation and Conditional Access. They should be tightly secured, monitored, tested, and used only for recovery.
Incorrect! Try again.
52A company regularly grants external consultants access to several Azure AD-integrated applications. Access must expire automatically, require sponsor approval, and be periodically recertified. Which Azure AD capability best fits the requirement?
Azure Active Directory (AAD) structure
Hard
A.Entitlement management access packages with expiration and access reviews
B.Administrative units with permanently assigned application administrators
C.Dynamic device groups based on the consultants' registered endpoints
D.Application proxy connectors combined with subscription-level Azure RBAC
Correct Answer: Entitlement management access packages with expiration and access reviews
Explanation:
Entitlement management supports governed external access through approval workflows, expiration, access packages, and recurring access reviews.
Incorrect! Try again.
53An Azure-hosted application must retrieve secrets from Key Vault without storing credentials in source code, configuration files, or deployment pipelines. Which identity approach is most appropriate?
Identity and Access Management (IAM)
Hard
A.Use a shared user account whose password is stored in the application database
B.Grant all application developers direct access to the Key Vault subscription
C.Create an application secret and embed it in an encrypted configuration file
D.Assign a managed identity and grant it narrowly scoped Key Vault permissions
Correct Answer: Assign a managed identity and grant it narrowly scoped Key Vault permissions
Explanation:
A managed identity eliminates application-managed credentials. Least-privilege Key Vault permissions restrict the identity to only the required secret operations.
Incorrect! Try again.
54A database uses customer-managed encryption keys stored in Key Vault. An internet-facing application is compromised, and its identity already has permission to decrypt and read the database records. What protection do the customer-managed keys provide against this attack?
Data breaches
Hard
A.They ensure stolen records remain encrypted after the application reads them
B.They automatically revoke the application identity after abnormal database activity
C.They prevent the compromised application from receiving plaintext database results
D.They provide little protection because the trusted application identity can decrypt data
Correct Answer: They provide little protection because the trusted application identity can decrypt data
Explanation:
Encryption at rest does not stop an authorized but compromised workload from reading plaintext. Least privilege, workload isolation, monitoring, and application security are also required.
Incorrect! Try again.
55A cloud provider supplies a current independent audit report demonstrating that its infrastructure meets a security standard. Why can the customer not treat the report as complete proof that its own workload is compliant?
Compliance risks
Hard
A.The report may cover provider controls but not customer identities, data, or configurations
B.Provider certifications become invalid whenever customers use managed cloud services
C.Compliance standards prohibit customers from relying on cloud provider evidence
D.Independent audit reports apply only when customers operate physical data centers
Correct Answer: The report may cover provider controls but not customer identities, data, or configurations
Explanation:
Provider assurance covers controls within the provider's responsibility. Customers must still demonstrate compliance for their configurations, access policies, applications, and data handling.
Incorrect! Try again.
56Users are repeatedly tricked into approving fraudulent push notifications generated through MFA fatigue attacks. Which replacement factor offers the strongest practical resistance to both push fatigue and credential phishing?
Multi-Factor Authentication (MFA)
Hard
A.Email verification links opened from the user's corporate mailbox
B.SMS one-time codes delivered to each user's registered mobile number
C.Time-based one-time passwords entered after the primary password
D.FIDO2 security keys or passkeys using origin-bound authentication
Correct Answer: FIDO2 security keys or passkeys using origin-bound authentication
Explanation:
FIDO2 authentication is phishing-resistant because credentials are bound to the legitimate origin. It also avoids approval prompts that attackers can exploit through push fatigue.
Incorrect! Try again.
57An engineer must start and stop one production virtual machine for a two-hour maintenance window each week. The engineer currently inherits Contributor access across the subscription. Which redesign best applies least privilege?
Identity and Access Management (IAM)
Hard
A.Retain Contributor access but require the engineer to submit weekly activity reports
B.Use a custom role at the VM scope with time-bound activation through PIM
C.Replace Contributor with permanent Virtual Machine Contributor at subscription scope
D.Assign Reader at the VM scope and Owner at the containing resource group
Correct Answer: Use a custom role at the VM scope with time-bound activation through PIM
Explanation:
A narrowly defined custom role limits permitted operations, VM-level scope limits affected resources, and PIM removes unnecessary standing access.
Incorrect! Try again.
58A database administrator can modify production records and delete the database audit logs that would reveal those modifications. Which architectural control most directly reduces this insider risk?
Insider threats
Hard
A.Allow the administrator to delete logs only during approved maintenance periods
B.Encrypt the database logs with a key available to the database administrator
C.Export append-only logs to a security account managed by independent personnel
D.Store additional copies of the audit logs on the same database server
Correct Answer: Export append-only logs to a security account managed by independent personnel
Explanation:
Independent administration and append-only storage create separation of duties and prevent the database administrator from altering both production data and its audit trail.
Incorrect! Try again.
59A web application's server-side request forgery vulnerability allows requests to the instance metadata service and exposes a workload identity token. Which measure most directly limits the resulting blast radius?
Common cloud security challenges
Hard
A.Increase the retention period of web application access logs and metrics
B.Place the application behind a global content delivery network endpoint
C.Encrypt the virtual machine's disks with a provider-managed encryption key
D.Grant the workload identity only the minimum permissions at the narrowest scope
Correct Answer: Grant the workload identity only the minimum permissions at the narrowest scope
Explanation:
If an attacker obtains the workload token, its effective permissions determine the blast radius. Narrow scope and least privilege limit what the stolen token can access.
Incorrect! Try again.
60Monitoring confirms that a compromised cloud virtual machine is actively exfiltrating data. Investigators need to stop further loss while preserving useful evidence. Which response is most appropriate?
Real-time scenario-based case studies
Hard
A.Network-isolate the VM, preserve disks and logs, then revoke exposed credentials
B.Patch the VM in place, clear temporary files, and return it to production monitoring
C.Leave the VM online until investigators complete a full review of its application logs
D.Power off the VM immediately, delete its disks, and rebuild it from the latest image
Correct Answer: Network-isolate the VM, preserve disks and logs, then revoke exposed credentials
Explanation:
Network isolation contains active exfiltration without immediately destroying volatile context. Preserving disks and centralized logs supports investigation, while credential revocation limits further access.
Incorrect! Try again.
Did this save you a night before the exam?
LPU Notes is free, and it stays free. Ads cover part of the server bill.
The rest comes out of a student's own pocket: the domain, the storage,
and keeping the site up through the weeks everyone needs it at once.
The payment button didn't load. An ad blocker or a filtered network is the usual reason.
to try again.
Nothing here is ever locked, and nothing unlocks. Chip in only if it was worth it.
What it pays for →