Unit 1: Understanding Cloud Security - Subjective Questions

INT328 — Network Virtualization And Cloud Security • Practice Questions with Detailed Answers

20 questions

1

Define cloud security and explain its major objectives and methods.

2

Explain the shared responsibility model of cloud security and discuss how responsibilities differ between a cloud service provider and a customer.

3

Compare IaaS, PaaS, and SaaS from a cloud security responsibility perspective.

4

Describe the common security challenges faced by organizations when adopting cloud computing.

5

What is a cloud data breach? Explain its major causes, effects, and preventive controls.

6

Distinguish between accidental and malicious insider threats in a cloud environment. Explain suitable mitigation measures.

7

Explain compliance risks in cloud computing and describe how an organization can manage them.

8

Define Identity and Access Management (IAM) and explain its role in cloud security.

9

Explain the principle of least privilege and role-based access control in cloud IAM. Illustrate their relationship with an example.

10

Describe the main structural components of Azure Active Directory (Microsoft Entra ID) and their relationships.

11

Explain how user and group management should be performed securely in Azure Active Directory.

12

What is Multi-Factor Authentication (MFA)? Explain its factors, benefits, and limitations.

13

Compare password-based authentication, app-based MFA, hardware security keys, and biometric authentication in terms of security and usability.

14

A company stores customer records in a cloud database, and an administrator discovers that the database was publicly accessible for three days. Analyze the likely causes and propose an incident-response plan.

15

An employee receives a convincing phishing message and approves an unexpected MFA prompt. Explain how the attack could succeed and design controls to reduce this risk.

16

Explain how encryption protects cloud data at rest and in transit. Identify important key-management practices.

17

Describe the role of logging, monitoring, and alerting in detecting cloud security incidents.

18

Explain the principle of defense in depth for cloud security and apply it to a cloud-hosted web application.

19

Distinguish authentication, authorization, and accounting in IAM, and explain why all three are needed.

20

A former contractor's Azure Active Directory account remains active and belongs to a group with access to confidential files. Analyze the security and compliance risks and recommend corrective actions.