Unit 1: Understanding Cloud Security - Practice Quiz

INT328 — Network Virtualization And Cloud Security 60 Questions
0 Correct 0 Wrong 60 Left
0/60

1 What is the primary purpose of cloud security?

Overview of cloud security and methods Easy
A. To replace all physical computers
B. To protect cloud data and services
C. To reduce application development time
D. To increase internet connection speed

2 Which cloud security method converts readable data into an unreadable form?

Overview of cloud security and methods Easy
A. Virtualization
B. Compression
C. Encryption
D. Replication

3 In the shared responsibility model, who is generally responsible for securing the physical cloud data center?

Shared responsibility model of cloud security Easy
A. The application user
B. The network visitor
C. The cloud provider
D. The cloud customer

4 In most cloud services, who is responsible for creating strong passwords for customer accounts?

Shared responsibility model of cloud security Easy
A. The internet provider
B. The building manager
C. The cloud customer
D. The hardware vendor

5 Which issue is a common cloud security challenge?

Common cloud security challenges Easy
A. Misconfigured storage
B. Faster processor speed
C. Shorter file names
D. Larger monitor size

6 What can happen when a cloud resource is configured with excessive permissions?

Common cloud security challenges Easy
A. Unauthorized users may gain access
B. Applications may use less memory
C. Files may become more compressed
D. Processors may run more quickly

7 What is a data breach?

Data breaches Easy
A. Unauthorized exposure of protected data
B. Routine backup of stored data
C. Scheduled deletion of duplicate data
D. Authorized transfer of public data

8 Which action can help reduce the impact of a stolen cloud database?

Data breaches Easy
A. Renaming stored files
B. Increasing screen brightness
C. Encrypting sensitive data
D. Sorting records alphabetically

9 Who can be considered an insider threat?

Insider threats Easy
A. An employee who misuses access
B. A visitor viewing a company website
C. A vendor selling computer hardware
D. A customer reading public content

10 Which security principle helps limit damage from an insider threat?

Insider threats Easy
A. Least privilege
B. Open access
C. Public storage
D. Password sharing

11 What does cloud compliance mainly involve?

Compliance risks Easy
A. Increasing the number of cloud servers
B. Changing the design of cloud applications
C. Improving the speed of cloud downloads
D. Following applicable laws and standards

12 Which activity helps an organization identify cloud compliance problems?

Compliance risks Easy
A. Conducting regular security audits
B. Changing desktop backgrounds
C. Renaming network devices
D. Increasing application font sizes

13 What is the main function of Identity and Access Management (IAM)?

Identity and Access Management (IAM) Easy
A. Increasing wireless signal strength
B. Cooling physical server rooms
C. Controlling access to resources
D. Compressing files before upload

14 Which IAM process confirms that a user is who they claim to be?

Identity and Access Management (IAM) Easy
A. Authorization
B. Accounting
C. Authentication
D. Archiving

15 In Azure Active Directory, what is a tenant?

Azure Active Directory (AAD) structure Easy
A. A physical storage device
B. A software testing method
C. A dedicated identity directory
D. A network routing protocol

16 Which item is commonly stored in an Azure Active Directory tenant?

Azure Active Directory (AAD) structure Easy
A. User identity
B. Processor temperature
C. Monitor resolution
D. Printer ink level

17 Why are users placed into groups in a cloud directory?

User and group management Easy
A. To increase account password length
B. To manage permissions collectively
C. To change file storage formats
D. To reduce network cable usage

18 What should an administrator do when an employee permanently leaves an organization?

User and group management Easy
A. Disable the employee's account
B. Share the employee's password
C. Increase the employee's permissions
D. Move the account to a public group

19 What does Multi-Factor Authentication (MFA) require?

Multi-Factor Authentication (MFA) Easy
A. Two or more usernames
B. Two or more email addresses
C. Two or more cloud providers
D. Two or more verification factors

20 A user receives an unexpected MFA approval request without trying to sign in. What should the user do?

Real-time scenario-based case studies Easy
A. Deny the request and report it
B. Approve the request immediately
C. Forward the request to coworkers
D. Disable all device notifications

21 An organization stores sensitive customer records in cloud object storage. Which combination of controls best protects the records against unauthorized disclosure?

Overview of cloud security and methods Medium
A. Data compression, replication, and load balancing
B. Auto-scaling, caching, and resource tagging
C. Encryption, least-privilege access, and activity logging
D. Version control, orchestration, and traffic shaping

22 A cloud administrator wants to identify virtual machines that are missing security patches. Which cloud security method is most appropriate?

Overview of cloud security and methods Medium
A. Continuous vulnerability assessment
B. Geographic traffic distribution
C. Federated identity management
D. Data loss prevention scanning

23 A company runs an application on an Infrastructure as a Service (IaaS) virtual machine. Who is normally responsible for patching the guest operating system?

Shared responsibility model of cloud security Medium
A. The hardware manufacturer
B. The customer organization
C. The network carrier alone
D. The cloud provider alone

24 A software company uses a managed Platform as a Service (PaaS) database. Which task is generally the cloud provider's responsibility?

Shared responsibility model of cloud security Medium
A. Defining the organization's retention policy
B. Assigning roles to business analysts
C. Maintaining the underlying database platform
D. Classifying the company's customer data

25 A development team creates cloud storage for testing and accidentally allows anonymous internet access. Which common cloud security challenge does this illustrate?

Common cloud security challenges Medium
A. Resource misconfiguration
B. Vendor lock-in
C. Capacity exhaustion
D. Network latency

26 An organization uses services from three cloud providers but cannot consistently monitor security events across them. Which action best addresses this challenge?

Common cloud security challenges Medium
A. Increase storage capacity in every cloud
B. Centralize logs in a security monitoring platform
C. Disable alerts generated by individual services
D. Move all workloads to public IP addresses

27 A storage access key is accidentally published in a public code repository. What should the security team do first?

Data breaches Medium
A. Increase the storage replication level
B. Rotate or revoke the exposed key
C. Archive the repository for future review
D. Rename the affected storage account

28 After detecting unusual downloads from a cloud database, which evidence would be most useful for determining which identity accessed the records?

Data breaches Medium
A. Resource pricing reports
B. Application design diagrams
C. Authentication and audit logs
D. Storage capacity metrics

29 A database administrator can both approve and execute the export of sensitive customer data. Which control would best reduce the insider threat?

Insider threats Medium
A. Automatic load balancing
B. Storage lifecycle management
C. Geographic replication
D. Separation of duties

30 An employee who is leaving the company begins downloading unusually large amounts of confidential data. Which control would most directly help detect and stop this behavior?

Insider threats Medium
A. A data loss prevention policy
B. A database indexing policy
C. A content delivery network
D. A virtual machine scale set

31 A regulation requires personal data to remain within a specific country. Which cloud design decision most directly supports this requirement?

Compliance risks Medium
A. Increasing the number of user accounts
B. Enabling automatic application scaling
C. Selecting an approved deployment region
D. Using larger virtual machine instances

32 An auditor asks the organization to prove that administrative actions are recorded and retained for one year. Which configuration best meets this requirement?

Compliance risks Medium
A. Enable encryption and rotate keys once each year
B. Enable audit logs and apply a one-year retention policy
C. Enable backups and retain only the latest copy
D. Enable auto-scaling and review usage each month

33 A support engineer needs permission to restart virtual machines but must not create, delete, or resize them. Which IAM approach is most appropriate?

Identity and Access Management (IAM) Medium
A. Assign the subscription owner role
B. Grant permanent global administrator access
C. Create a least-privilege custom role
D. Share an administrator account

34 A company wants employees to access several cloud applications by authenticating once with the corporate identity provider. Which IAM capability should it implement?

Identity and Access Management (IAM) Medium
A. Network peering
B. Database replication
C. Single sign-on
D. Disk encryption

35 A company has several Azure subscriptions that should use the same employee identities. Which arrangement supports this requirement?

Azure Active Directory (AAD) structure Medium
A. Create local accounts on every Azure resource
B. Associate the subscriptions with one AAD tenant
C. Associate each user with a different subscription
D. Create a separate tenant for every virtual machine

36 A partner must access an application in the company's Azure Active Directory tenant while continuing to use the partner organization's credentials. Which feature is most suitable?

Azure Active Directory (AAD) structure Medium
A. AAD self-service password reset
B. Azure resource lock management
C. Azure virtual network peering
D. AAD business-to-business guest access

37 All members of the Finance department need the same access to a reporting application. What is the most manageable approach?

User and group management Medium
A. Grant access through public application links
B. Assign access to a Finance security group
C. Assign access separately to each user
D. Create one shared Finance user account

38 An AAD dynamic group should contain all active users whose department attribute is set to Sales. What is the main management benefit?

User and group management Medium
A. Membership updates automatically from user attributes
B. Every member receives global administrator rights
C. Membership remains fixed after group creation
D. Users can bypass application authorization checks

39 An attacker obtains an employee's cloud password through phishing. Why can MFA still prevent account access?

Multi-Factor Authentication (MFA) Medium
A. It automatically deletes the stolen password
B. It blocks all access from external networks
C. It requires an additional verification factor
D. It hides the account's username from attackers

40 A remote administrator signs in from an unfamiliar country and attempts to modify production firewall rules. Which response best balances security and legitimate access?

Real-time scenario-based case studies Medium
A. Allow the sign-in because the password is correct
B. Delete the administrator account immediately
C. Disable all production firewall protections
D. Require MFA and verify the sign-in risk

41 An enterprise needs continuous detection of publicly exposed storage, overly permissive IAM policies, and configuration drift across hundreds of cloud subscriptions. Which security method most directly addresses this requirement?

Overview of cloud security and methods Hard
A. Forward application events to a centralized security information system
B. Implement Cloud Security Posture Management across the subscriptions
C. Deploy a Cloud Access Security Broker to inspect user traffic
D. Install Cloud Workload Protection agents on all compute instances

42 A company deploys an application on a managed Platform as a Service offering. A vulnerability is discovered in an application library packaged by the development team, while the underlying operating system is fully patched. Who is primarily responsible for remediating the library?

Shared responsibility model of cloud security Hard
A. The provider, because it patches the platform operating system
B. The provider, because it operates the managed application platform
C. The customer, because it controls the application and its dependencies
D. The customer, because it owns the physical infrastructure configuration

43 A cloud environment creates and deletes serverless resources within minutes. A nightly scanner repeatedly misses vulnerable resources that existed long enough to process sensitive data. Which change best addresses this visibility gap?

Common cloud security challenges Hard
A. Use event-driven discovery and policy enforcement during resource creation
B. Replace serverless resources with permanently running virtual machines
C. Increase the nightly scanner's vulnerability severity threshold
D. Retain application data longer so scanners can inspect it later

44 An attacker obtains a cloud administrator credential and attempts to erase evidence after downloading sensitive objects. Which preconfigured control would provide the strongest support for reconstructing the breach?

Data breaches Hard
A. Export audit logs to immutable storage under a separate security account
B. Store administrative activity logs on each administrator's workstation
C. Enable detailed logging within the same compromised cloud subscription
D. Retain database transaction logs on the affected database server

45 A production administrator requires privileged access for occasional maintenance but must not approve their own requests. Access must expire automatically, and every activation must be auditable. Which design best satisfies these requirements?

Insider threats Hard
A. Grant standing access but require a second factor during interactive login
B. Assign permanent access and review the administrator's activity quarterly
C. Use just-in-time privileged access with approval and time-bound activation
D. Share an administrative account whose password rotates after each session

46 A regulated workload must keep all customer records within one approved country. The primary database is correctly located, but automated backups are copied to a provider-managed recovery region abroad. Encryption is enabled. What is the principal compliance issue?

Compliance risks Hard
A. Only the primary database matters because backups are not active records
B. Backup location may violate residency rules despite encryption at rest
C. Provider-managed recovery regions are automatically exempt from regulation
D. Encryption removes the residency risk because foreign backups are unreadable

47 An Azure user receives the Owner role at the subscription scope. A deny assignment at a child resource group prohibits deletion of virtual networks and applies to that user. What happens when the user attempts such a deletion in the resource group?

Identity and Access Management (IAM) Hard
A. The deletion succeeds because a subscription-level role overrides child controls
B. The deletion is blocked only if the user also has a resource-group role
C. The deletion is blocked because the applicable deny assignment takes precedence
D. The deletion succeeds because the Owner role includes all management actions

48 Which statement correctly describes the relationship between an Azure Active Directory tenant and Azure subscriptions?

Azure Active Directory (AAD) structure Hard
A. Every subscription maintains an independent directory that cannot be changed
B. A tenant can be associated with only one subscription throughout its lifetime
C. A subscription can simultaneously trust several directories for authentication
D. One tenant can serve multiple subscriptions, while each subscription trusts one tenant

49 A synchronized user's department attribute changes from Sales to Finance. Two minutes later, the user is still absent from an Azure AD dynamic group whose rule includes users with department equal to Finance. Audit records confirm that the new attribute is present. What is the most likely explanation?

User and group management Hard
A. Department attributes can be used only with assigned security group membership
B. The user must sign out before the dynamic group rule can evaluate the attribute
C. Dynamic membership reevaluation is asynchronous and may not have completed
D. Dynamic groups cannot evaluate attributes synchronized from on-premises systems

50 An organization enables MFA for all users, yet an attacker successfully authenticates to a mailbox using a stolen password through an older email protocol. Which control gap most plausibly enabled the attack?

Multi-Factor Authentication (MFA) Hard
A. Password synchronization caused the second factor to be cached indefinitely
B. Legacy authentication was permitted even though it could not perform MFA
C. Group-based licensing prevented MFA from applying to cloud applications
D. Self-service password reset automatically exempted the mailbox from MFA

51 A tenant-wide Conditional Access policy requires federated authentication and MFA for every administrator. During an outage of the external identity provider, no administrator can sign in. Which prior design would have provided the safest recovery path?

Real-time scenario-based case studies Hard
A. Create a shared Global Administrator account protected by a rotating password
B. Maintain two monitored cloud-only emergency accounts excluded from the policy
C. Disable audit logging for one administrator to ensure uninterrupted access
D. Give every administrator a permanent password that bypasses federation failures

52 A company regularly grants external consultants access to several Azure AD-integrated applications. Access must expire automatically, require sponsor approval, and be periodically recertified. Which Azure AD capability best fits the requirement?

Azure Active Directory (AAD) structure Hard
A. Entitlement management access packages with expiration and access reviews
B. Administrative units with permanently assigned application administrators
C. Dynamic device groups based on the consultants' registered endpoints
D. Application proxy connectors combined with subscription-level Azure RBAC

53 An Azure-hosted application must retrieve secrets from Key Vault without storing credentials in source code, configuration files, or deployment pipelines. Which identity approach is most appropriate?

Identity and Access Management (IAM) Hard
A. Use a shared user account whose password is stored in the application database
B. Grant all application developers direct access to the Key Vault subscription
C. Create an application secret and embed it in an encrypted configuration file
D. Assign a managed identity and grant it narrowly scoped Key Vault permissions

54 A database uses customer-managed encryption keys stored in Key Vault. An internet-facing application is compromised, and its identity already has permission to decrypt and read the database records. What protection do the customer-managed keys provide against this attack?

Data breaches Hard
A. They ensure stolen records remain encrypted after the application reads them
B. They automatically revoke the application identity after abnormal database activity
C. They prevent the compromised application from receiving plaintext database results
D. They provide little protection because the trusted application identity can decrypt data

55 A cloud provider supplies a current independent audit report demonstrating that its infrastructure meets a security standard. Why can the customer not treat the report as complete proof that its own workload is compliant?

Compliance risks Hard
A. The report may cover provider controls but not customer identities, data, or configurations
B. Provider certifications become invalid whenever customers use managed cloud services
C. Compliance standards prohibit customers from relying on cloud provider evidence
D. Independent audit reports apply only when customers operate physical data centers

56 Users are repeatedly tricked into approving fraudulent push notifications generated through MFA fatigue attacks. Which replacement factor offers the strongest practical resistance to both push fatigue and credential phishing?

Multi-Factor Authentication (MFA) Hard
A. Email verification links opened from the user's corporate mailbox
B. SMS one-time codes delivered to each user's registered mobile number
C. Time-based one-time passwords entered after the primary password
D. FIDO2 security keys or passkeys using origin-bound authentication

57 An engineer must start and stop one production virtual machine for a two-hour maintenance window each week. The engineer currently inherits Contributor access across the subscription. Which redesign best applies least privilege?

Identity and Access Management (IAM) Hard
A. Retain Contributor access but require the engineer to submit weekly activity reports
B. Use a custom role at the VM scope with time-bound activation through PIM
C. Replace Contributor with permanent Virtual Machine Contributor at subscription scope
D. Assign Reader at the VM scope and Owner at the containing resource group

58 A database administrator can modify production records and delete the database audit logs that would reveal those modifications. Which architectural control most directly reduces this insider risk?

Insider threats Hard
A. Allow the administrator to delete logs only during approved maintenance periods
B. Encrypt the database logs with a key available to the database administrator
C. Export append-only logs to a security account managed by independent personnel
D. Store additional copies of the audit logs on the same database server

59 A web application's server-side request forgery vulnerability allows requests to the instance metadata service and exposes a workload identity token. Which measure most directly limits the resulting blast radius?

Common cloud security challenges Hard
A. Increase the retention period of web application access logs and metrics
B. Place the application behind a global content delivery network endpoint
C. Encrypt the virtual machine's disks with a provider-managed encryption key
D. Grant the workload identity only the minimum permissions at the narrowest scope

60 Monitoring confirms that a compromised cloud virtual machine is actively exfiltrating data. Investigators need to stop further loss while preserving useful evidence. Which response is most appropriate?

Real-time scenario-based case studies Hard
A. Network-isolate the VM, preserve disks and logs, then revoke exposed credentials
B. Patch the VM in place, clear temporary files, and return it to production monitoring
C. Leave the VM online until investigators complete a full review of its application logs
D. Power off the VM immediately, delete its disks, and rebuild it from the latest image