1Which security model assumes that no user or device should be trusted automatically?
Latest trends in cloud security
Easy
A.Local Trust
B.Shared Hosting
C.Zero Trust
D.Open Access
Correct Answer: Zero Trust
Explanation:
Zero Trust requires every user, device, and access request to be verified.
Incorrect! Try again.
2Which recent cloud security trend focuses on protecting applications throughout their development lifecycle?
Latest trends in cloud security
Easy
A.Data caching
B.DevSecOps
C.Server scaling
D.Load balancing
Correct Answer: DevSecOps
Explanation:
DevSecOps integrates security into software development and operations processes.
Incorrect! Try again.
3What does a cloud-native security approach primarily protect?
Latest trends in cloud security
Easy
A.Desktop wallpapers
B.Physical notebooks
C.Cloud-based applications
D.Printed documents
Correct Answer: Cloud-based applications
Explanation:
Cloud-native security is designed for applications, services, and infrastructure operating in cloud environments.
Incorrect! Try again.
4How can artificial intelligence help improve cloud security?
Artificial intelligence in cloud security
Easy
A.By increasing screen brightness
B.By detecting unusual activity
C.By replacing network cables
D.By reducing storage capacity
Correct Answer: By detecting unusual activity
Explanation:
AI can analyze activity patterns and identify behavior that may indicate a security threat.
Incorrect! Try again.
5What type of data can an AI security system analyze to identify possible cloud attacks?
Artificial intelligence in cloud security
Easy
A.Monitor color settings
B.Network traffic patterns
C.Document page margins
D.Keyboard layout choices
Correct Answer: Network traffic patterns
Explanation:
AI systems can examine network traffic patterns to detect anomalies and possible attacks.
Incorrect! Try again.
6Which task can AI automate in a cloud security system?
Artificial intelligence in cloud security
Easy
A.Cable manufacturing
B.Office scheduling
C.Hardware painting
D.Threat detection
Correct Answer: Threat detection
Explanation:
AI can automatically detect potential threats by analyzing large amounts of security data.
Incorrect! Try again.
7Where does edge computing process data?
Edge computing
Easy
A.Only in a central cloud
B.Only in an offline archive
C.Near the data source
D.Inside a backup facility
Correct Answer: Near the data source
Explanation:
Edge computing processes data close to where it is created, reducing delays and network usage.
Incorrect! Try again.
8What is a major benefit of edge computing?
Edge computing
Easy
A.Longer response delays
B.Higher network dependence
C.Slower device communication
D.Lower processing latency
Correct Answer: Lower processing latency
Explanation:
Processing data near its source reduces transmission time and lowers latency.
Incorrect! Try again.
9Why must edge devices be secured?
Edge computing
Easy
A.They always operate without data
B.They cannot connect to networks
C.They may handle sensitive data
D.They replace all cloud servers
Correct Answer: They may handle sensitive data
Explanation:
Edge devices often collect or process sensitive data and can become targets for attackers.
Incorrect! Try again.
10Quantum cryptography is based primarily on principles from which field?
Quantum cryptography
Easy
A.Database design
B.Classical mechanics
C.Quantum mechanics
D.Civil engineering
Correct Answer: Quantum mechanics
Explanation:
Quantum cryptography applies principles of quantum mechanics to secure communication.
Incorrect! Try again.
11What is the main purpose of quantum key distribution?
Quantum cryptography
Easy
A.To compress cloud files quickly
B.To exchange encryption keys securely
C.To create user interfaces
D.To increase processor speed
Correct Answer: To exchange encryption keys securely
Explanation:
Quantum key distribution allows encryption keys to be shared while helping reveal interception attempts.
Incorrect! Try again.
12What may happen when an attacker observes information in a quantum communication channel?
Quantum cryptography
Easy
A.The network speed may double
B.The storage size may increase
C.The quantum state may change
D.The cloud account may close
Correct Answer: The quantum state may change
Explanation:
Measuring quantum information can alter its state, making possible interception detectable.
Incorrect! Try again.
13Which practice helps secure a newly deployed cloud service?
Secure cloud deployment
Easy
A.Allowing unrestricted access
B.Changing default credentials
C.Sharing administrator passwords
D.Disabling security updates
Correct Answer: Changing default credentials
Explanation:
Default credentials should be replaced because attackers may already know them.
Incorrect! Try again.
14Which access principle should be used during secure cloud deployment?
Secure cloud deployment
Easy
A.Unlimited privilege
B.Least privilege
C.Permanent privilege
D.Anonymous privilege
Correct Answer: Least privilege
Explanation:
Least privilege gives users and services only the permissions needed to perform their tasks.
Incorrect! Try again.
15What protects sensitive cloud data from being easily read if it is intercepted?
Secure cloud deployment
Easy
A.Compression
B.Encryption
C.Indexing
D.Replication
Correct Answer: Encryption
Explanation:
Encryption converts data into an unreadable form that requires a key to access.
Incorrect! Try again.
16What is the main purpose of a regular cloud security audit?
Regular audits
Easy
A.To review security controls
B.To organize office equipment
C.To design application logos
D.To increase display quality
Correct Answer: To review security controls
Explanation:
A security audit checks whether controls, policies, and configurations are effective and compliant.
Incorrect! Try again.
17How often should cloud security audits generally be performed?
Regular audits
Easy
A.Only when users complain
B.Only after every attack
C.At planned regular intervals
D.Once before initial deployment
Correct Answer: At planned regular intervals
Explanation:
Regularly scheduled audits help organizations find problems before they lead to serious incidents.
Incorrect! Try again.
18What is the primary goal of a vulnerability assessment?
Vulnerability assessments
Easy
A.To purchase cloud storage
B.To identify security weaknesses
C.To create employee accounts
D.To improve screen resolution
Correct Answer: To identify security weaknesses
Explanation:
A vulnerability assessment searches systems and applications for weaknesses that attackers could exploit.
Incorrect! Try again.
19What commonly happens after vulnerabilities are discovered?
Vulnerability assessments
Easy
A.They are prioritized for remediation
B.They are published as passwords
C.They are converted into backups
D.They are ignored permanently
Correct Answer: They are prioritized for remediation
Explanation:
Discovered vulnerabilities are usually ranked by risk so the most serious ones can be fixed first.
Incorrect! Try again.
20What does a proactive cloud security posture emphasize?
Proactive security posture
Easy
A.Responding only after incidents
B.Ignoring low-risk warnings
C.Preventing threats before incidents
D.Removing all security monitoring
Correct Answer: Preventing threats before incidents
Explanation:
A proactive security posture identifies and reduces risks before they become security incidents.
Incorrect! Try again.
21A company uses multiple cloud providers and wants one system to enforce consistent identity, logging, and policy controls across all environments. Which trend best addresses this requirement?
Latest trends in cloud security
Medium
A.Multicloud security management
B.Cloud-native security platforms
C.Traditional perimeter firewalls
D.Local hardware encryption
Correct Answer: Multicloud security management
Explanation:
Multicloud security management provides centralized visibility and consistent controls across different cloud providers.
Incorrect! Try again.
22A development team frequently deploys containers and serverless functions. Which security practice is most aligned with current cloud security trends?
Latest trends in cloud security
Medium
A.Restricting all workloads to physical servers
B.Embedding security throughout the development pipeline
C.Testing security only after deployment
D.Disabling automated deployment tools
Correct Answer: Embedding security throughout the development pipeline
Explanation:
DevSecOps integrates security checks into development and deployment workflows, allowing risks to be identified earlier.
Incorrect! Try again.
23An organization wants to verify that users and devices are trusted for every cloud access request, even when they are inside the corporate network. Which approach should it adopt?
Latest trends in cloud security
Medium
A.A shared administrator account
B.A larger network perimeter
C.A zero-trust security model
D.A permanent VPN connection
Correct Answer: A zero-trust security model
Explanation:
Zero trust continuously verifies identity, device status, and access context instead of automatically trusting internal network locations.
Incorrect! Try again.
24An AI security system detects that an employee's account suddenly accesses data from two distant countries within a few minutes. What capability is the system applying?
Artificial intelligence in cloud security
Medium
A.Routine backup scheduling
B.Behavioral anomaly detection
C.Network address translation
D.Static password validation
Correct Answer: Behavioral anomaly detection
Explanation:
Behavioral anomaly detection identifies activity that differs significantly from an account's normal usage patterns.
Incorrect! Try again.
25A cloud security model is trained using historical incidents, but its alerts increase significantly after a major change in user behavior. What is the most appropriate response?
Artificial intelligence in cloud security
Medium
A.Delete the historical training data
B.Disable all automated alerts
C.Grant broader access to users
D.Retrain and validate the model
Correct Answer: Retrain and validate the model
Explanation:
Changing behavior can reduce model accuracy, so retraining with current data and validating performance helps limit false positives and missed threats.
Incorrect! Try again.
26An AI tool recommends isolating a production workload after detecting suspicious activity. What should a security analyst do before allowing automatic isolation?
Artificial intelligence in cloud security
Medium
A.Remove the workload's audit records
B.Review the recommendation and its evidence
C.Approve every recommendation immediately
D.Ignore the recommendation permanently
Correct Answer: Review the recommendation and its evidence
Explanation:
Analyst review helps confirm that the recommendation is accurate and that isolation will not cause unnecessary operational disruption.
Incorrect! Try again.
27A healthcare provider processes patient-monitoring data at edge locations to reduce latency. Which security control is especially important for these distributed sites?
Edge computing
Medium
A.A single unchanging administrator password
B.Removing authentication from local devices
C.Disabling local system updates
D.Physical and remote device protection
Correct Answer: Physical and remote device protection
Explanation:
Edge devices may be physically exposed and remotely distributed, so they require strong physical security, authentication, monitoring, and update controls.
Incorrect! Try again.
28An edge device continues collecting sensitive data when its connection to the central cloud is interrupted. Which design choice best reduces security risk?
Edge computing
Medium
A.Apply local encryption and retention limits
B.Transmit data through an open wireless network
C.Disable all local access controls
D.Store data indefinitely on the device
Correct Answer: Apply local encryption and retention limits
Explanation:
Encryption protects locally stored data, while retention limits reduce the amount of sensitive information exposed if the device is compromised.
Incorrect! Try again.
29A company deploys thousands of edge sensors from different manufacturers. Which approach best supports consistent security management?
Edge computing
Medium
A.Allow each sensor to select its own credentials
B.Update sensors only after an incident
C.Use standardized secure onboarding procedures
D.Permit unrestricted communication between sensors
Correct Answer: Use standardized secure onboarding procedures
Explanation:
Standardized onboarding establishes trusted identities, secure credentials, and baseline configurations across a large and diverse edge environment.
Incorrect! Try again.
30A financial institution is concerned that encrypted data captured today could be decrypted by future quantum computers. Which strategy best addresses this risk?
Post-quantum cryptographic algorithms are designed to resist attacks from both current systems and future quantum computers.
Incorrect! Try again.
31In quantum key distribution, an unauthorized party measures photons while attempting to intercept a key. What security property helps reveal the interception?
Quantum cryptography
Medium
A.Network addresses hide the key
B.Measurement can disturb quantum states
C.Photons automatically duplicate themselves
D.Keys are stored in plain text
Correct Answer: Measurement can disturb quantum states
Explanation:
Quantum measurements can alter the states of transmitted particles, allowing communicating parties to detect possible interception.
Incorrect! Try again.
32A cloud provider is planning a long-term migration to post-quantum security. Which preparation is most practical before replacing all current cryptographic systems?
A cryptographic inventory identifies algorithms, keys, protocols, and data lifetimes that must be addressed during a post-quantum migration.
Incorrect! Try again.
33A team is deploying a cloud application that stores customer records. Which configuration most directly reduces unauthorized access?
Secure cloud deployment
Medium
A.Public storage with a complex file name
B.Default permissions with rotating usernames
C.Private storage with least-privilege roles
D.Shared storage with anonymous read access
Correct Answer: Private storage with least-privilege roles
Explanation:
Private storage and least-privilege roles ensure that only approved identities receive the minimum access required.
Incorrect! Try again.
34A deployment pipeline creates cloud resources from approved templates. A security engineer wants to prevent insecure configurations before deployment. Which control is most suitable?
Scanning infrastructure-as-code templates can identify risky permissions, exposed services, and insecure settings before resources are created.
Incorrect! Try again.
35During a cloud audit, an organization discovers that several inactive accounts still have administrative permissions. What should be done first?
Regular audits
Medium
A.Export the accounts to a public report
B.Remove or disable unnecessary accounts
C.Create additional administrator accounts
D.Ignore the accounts until the next audit
Correct Answer: Remove or disable unnecessary accounts
Explanation:
Removing unused privileged accounts reduces the attack surface and prevents those credentials from being misused.
Incorrect! Try again.
36A company wants its cloud audit findings to be useful for improving security over time. Which practice is most effective?
Regular audits
Medium
A.Track findings through documented remediation
B.Record only successful control tests
C.Delete findings after management review
D.Perform audits without assigning owners
Correct Answer: Track findings through documented remediation
Explanation:
Assigning owners, deadlines, and verification steps ensures that audit findings result in measurable security improvements.
Incorrect! Try again.
37A vulnerability scanner reports a critical issue in a public-facing virtual machine. What factor should primarily influence remediation priority?
Vulnerability assessments
Medium
A.The age of the scanning tool
B.The issue's risk and exposure
C.The virtual machine's display name
D.The number of installed applications
Correct Answer: The issue's risk and exposure
Explanation:
Vulnerabilities that are severe and exposed to the internet generally require faster remediation than lower-risk or isolated findings.
Incorrect! Try again.
38A scan identifies a vulnerability in a cloud service, but the service is protected by strict network controls and is not internet-facing. How should the result be handled?
Vulnerability assessments
Medium
A.Ignore it because exposure is limited
B.Publish the vulnerability without verification
C.Immediately delete the entire cloud account
D.Assess context and plan appropriate remediation
Correct Answer: Assess context and plan appropriate remediation
Explanation:
Network isolation lowers immediate exposure but does not eliminate the vulnerability, so its overall risk and remediation needs should still be assessed.
Incorrect! Try again.
39A security team continuously monitors cloud configurations and automatically compares them with approved baselines. What security objective does this primarily support?
Proactive security posture
Medium
A.Increasing the number of cloud regions
B.Detecting and correcting configuration drift
C.Replacing all incident response procedures
D.Eliminating the need for user training
Correct Answer: Detecting and correcting configuration drift
Explanation:
Continuous comparison with approved baselines reveals unauthorized or accidental changes before they create significant exposure.
Incorrect! Try again.
40A company conducts tabletop exercises for a possible cloud ransomware incident. Which benefit most directly supports a proactive security posture?
Proactive security posture
Medium
A.Improving response readiness before an incident
B.Replacing encryption with faster networking
C.Reducing the need for system monitoring
D.Guaranteeing that attacks cannot occur
Correct Answer: Improving response readiness before an incident
Explanation:
Tabletop exercises reveal gaps in roles, communication, backups, and recovery procedures before a real incident occurs.
Incorrect! Try again.
41An enterprise operates Kubernetes clusters, serverless functions, and virtual machines across three cloud providers. Security teams receive thousands of isolated findings without knowing which findings form exploitable attack paths. Which modernization most directly addresses this problem?
Latest trends in cloud security
Hard
A.Replace provider-native security services with a single perimeter firewall platform
B.Deploy separate signature-based IDS appliances within every cloud virtual network
C.Consolidate infrastructure logs into a centralized long-term archival storage account
D.Adopt a CNAPP that correlates identities, configurations, vulnerabilities, workloads, and attack paths
Correct Answer: Adopt a CNAPP that correlates identities, configurations, vulnerabilities, workloads, and attack paths
Explanation:
A Cloud-Native Application Protection Platform correlates posture, entitlement, workload, and vulnerability data, allowing teams to prioritize findings that create reachable attack paths.
Incorrect! Try again.
42A multi-cloud organization is replacing network-location trust with identity-centric controls. Which design most closely implements a cloud-native Zero Trust model?
Latest trends in cloud security
Hard
A.Grant access to cloud accounts after authenticating once through a centralized VPN
B.Grant access through long-lived service credentials restricted by source IP addresses
C.Grant access after continuously evaluating workload identity, device state, context, and policy
D.Grant access to all resources after a user enters the corporate private network
Correct Answer: Grant access after continuously evaluating workload identity, device state, context, and policy
Explanation:
Zero Trust uses explicit, contextual, and continuously evaluated authorization rather than assuming that network location or an earlier authentication event remains trustworthy.
Incorrect! Try again.
43A behavioral model retrained from recent cloud telemetry gradually stops flagging a malicious API sequence because an attacker repeatedly injects similar low-volume events into the training stream. What is the most appropriate primary defense?
Artificial intelligence in cloud security
Hard
A.Allow the model to retrain automatically whenever its alert volume falls below baseline
B.Use provenance-verified training data, poisoning detection, and independently validated model versions
C.Increase the model learning rate so that new API sequences are incorporated more quickly
D.Remove historical observations so that the model emphasizes current production behavior
Correct Answer: Use provenance-verified training data, poisoning detection, and independently validated model versions
Explanation:
The scenario is an online data-poisoning attack. Trusted data provenance, poisoning checks, and controlled model promotion prevent attacker-influenced telemetry from silently redefining normal behavior.
Incorrect! Try again.
44An AI detector is evaluated under the cost function , where is the number of false negatives and is the number of false positives. Which operating point minimizes cost?
Artificial intelligence in cloud security
Hard
A.
B.
C.
D.
Correct Answer:
Explanation:
The respective costs are , , , and . The first operating point therefore minimizes the weighted error cost.
Incorrect! Try again.
45A cloud anomaly model has stable test accuracy but produces increasing false positives after a major migration from virtual machines to serverless workloads. Which response best addresses the likely cause without weakening detection globally?
Artificial intelligence in cloud security
Hard
A.Measure feature drift, segment by workload type, and retrain using validated serverless telemetry
B.Replace behavioral detection with static signatures derived from historical virtual-machine incidents
C.Raise one global anomaly threshold until the total alert count returns to its previous level
D.Suppress all alerts associated with newly created serverless functions for an initial period
Correct Answer: Measure feature drift, segment by workload type, and retrain using validated serverless telemetry
Explanation:
The architecture change likely caused distribution drift. Segmented evaluation and controlled retraining adapt the model while preserving sensitivity for other workload classes.
Incorrect! Try again.
46Edge gateways must authorize safety-critical commands during intermittent disconnection from the central cloud. Which architecture best balances availability with bounded security risk?
Edge computing
Hard
A.Cache administrator passwords locally and replay cloud authentication when connectivity returns
B.Use short-lived signed capabilities, locally cached policy, secure time, and deny-by-default expiry
C.Permit all previously observed commands until the gateway reconnects to the central policy engine
D.Disable authorization during outages while retaining encrypted logging for later cloud inspection
Correct Answer: Use short-lived signed capabilities, locally cached policy, secure time, and deny-by-default expiry
Explanation:
Signed, time-bounded capabilities and cached policy support disconnected operation while limiting stale authorization. Secure time and fail-closed expiry constrain replay and prolonged misuse.
Incorrect! Try again.
47A cloud service must release decryption keys only to edge nodes running approved firmware and an untampered boot chain. Which mechanism most directly provides this assurance?
Edge computing
Hard
A.Verify that the node communicates through an encrypted provider-managed network tunnel
B.Verify hardware-rooted remote-attestation evidence before issuing an ephemeral key
C.Verify that the node presents a certificate issued by the enterprise certificate authority
D.Verify that the node reports the expected operating-system version in its inventory record
Correct Answer: Verify hardware-rooted remote-attestation evidence before issuing an ephemeral key
Explanation:
Remote attestation cryptographically reports measured boot state through a hardware root of trust. A certificate or tunnel authenticates an endpoint but does not prove its current software state.
Incorrect! Try again.
48Thousands of edge sensors contribute measurements to a cloud analytics service, but individual readings must remain hidden from both the network and the aggregator. The cloud needs only the sum of all readings. Which approach is most suitable?
Edge computing
Hard
A.Apply deterministic encryption so identical individual measurements remain searchable in storage
B.Apply transport encryption and decrypt every individual measurement at the cloud load balancer
C.Apply secure aggregation so the cloud recovers the aggregate without individual measurements
D.Apply tokenization at the cloud gateway after each individual measurement has been received
Correct Answer: Apply secure aggregation so the cloud recovers the aggregate without individual measurements
Explanation:
Secure aggregation allows computation of a collective result while preventing the aggregator from learning each participant's plaintext contribution.
Incorrect! Try again.
49Two data centers use quantum key distribution to generate symmetric keys. Why is an authenticated classical channel still required?
Quantum cryptography
Hard
A.Without classical authentication, generated keys cannot be used by symmetric encryption algorithms
B.Without classical authentication, an active attacker can impersonate both QKD endpoints
C.Without classical authentication, quantum states cannot travel through an optical transmission medium
Correct Answer: Without classical authentication, an active attacker can impersonate both QKD endpoints
Explanation:
QKD can reveal eavesdropping on the quantum channel, but it does not inherently establish endpoint identity. Authentication is required to prevent man-in-the-middle impersonation.
Incorrect! Try again.
50An organization fears that adversaries are collecting encrypted traffic now for future quantum decryption. Which migration strategy provides the strongest practical transition for key establishment?
Quantum cryptography
Hard
A.Increase RSA modulus sizes while retaining the same certificate and exchange protocols
B.Use a validated hybrid exchange combining classical and post-quantum shared secrets
C.Encrypt each session twice with independent AES-256 keys derived from classical RSA
D.Replace public-key exchange with reusable symmetric keys distributed through cloud storage
Correct Answer: Use a validated hybrid exchange combining classical and post-quantum shared secrets
Explanation:
A properly designed hybrid exchange combines classical and post-quantum mechanisms, reducing transition risk and protecting recorded traffic against future quantum-capable attacks.
Incorrect! Try again.
51A production resource is manually modified after deployment, creating a difference from its reviewed Infrastructure as Code template. Which control most effectively prevents the modification from becoming a persistent hidden state?
Secure cloud deployment
Hard
A.Continuously detect drift and reconcile or redeploy resources from the approved immutable definition
B.Permit emergency modifications if administrators document their intended changes in a ticket
C.Record administrator commands and review the activity during the next quarterly compliance meeting
D.Back up the modified resource state so the manual configuration can be restored after a failure
Correct Answer: Continuously detect drift and reconcile or redeploy resources from the approved immutable definition
Explanation:
Drift detection identifies divergence, while reconciliation or immutable redeployment restores the reviewed desired state instead of allowing undocumented configuration to persist.
Incorrect! Try again.
52A Kubernetes deployment pipeline must prevent containers from reaching production if they are unsigned, request privileged execution, or contain critical exploitable packages. Where should enforcement primarily occur?
Secure cloud deployment
Hard
A.At runtime using log analysis after the containers have started serving production traffic
B.At the registry using repository naming rules and periodic manual image-tag inspections
C.At admission using signed provenance, policy-as-code, and vulnerability decision criteria
D.At the network layer using ingress filtering and encrypted service-to-service communication
Correct Answer: At admission using signed provenance, policy-as-code, and vulnerability decision criteria
Explanation:
Admission controls can reject noncompliant workloads before execution by evaluating signatures, provenance, security context, and vulnerability policy.
Incorrect! Try again.
53A microservice currently stores a long-lived cloud API key in an encrypted environment variable. Which redesign best reduces secret theft and rotation risk?
Secure cloud deployment
Hard
A.Rotate the encrypted API key annually and inject it through a protected build pipeline
B.Use workload identity federation to obtain short-lived, narrowly scoped credentials
C.Store the API key in a private source repository restricted to deployment administrators
D.Split the API key across two environment variables reconstructed when the service starts
Correct Answer: Use workload identity federation to obtain short-lived, narrowly scoped credentials
Explanation:
Workload identity removes persistent embedded secrets and supplies temporary credentials bound to a verified workload identity and least-privilege permissions.
Incorrect! Try again.
54An auditor finds that storage encryption was enabled on the audit date, but the organization cannot prove it remained enabled throughout the year. Which evidence would best address the deficiency?
Regular audits
Hard
A.Immutable time-stamped configuration history showing continuous control state and detected changes
B.A current asset inventory listing the storage service as subject to the encryption policy
C.A management statement confirming that encryption was intended to remain enabled all year
D.A screenshot of the encrypted storage settings captured during the auditor's final interview
Correct Answer: Immutable time-stamped configuration history showing continuous control state and detected changes
Explanation:
Point-in-time evidence does not establish continuous operation. Immutable historical configuration evidence demonstrates whether the control remained effective across the audit period.
Incorrect! Try again.
55A SaaS provider claims that all security controls are covered by the cloud infrastructure provider's compliance report. What should an auditor examine first?
Regular audits
Hard
A.The infrastructure provider's total number of certifications and global data-center regions
B.The infrastructure provider's uptime history and publicly announced service-level objectives
C.The shared-responsibility mapping, complementary controls, service scope, and report exceptions
D.The SaaS provider's marketing description of encryption and high-availability capabilities
Correct Answer: The shared-responsibility mapping, complementary controls, service scope, and report exceptions
Explanation:
Provider reports cover defined systems and controls, not every customer responsibility. Scope, exceptions, and complementary user-entity controls reveal what the SaaS provider must implement.
Incorrect! Try again.
56Four vulnerable assets require prioritization. Which should be remediated first when using an exposure-aware risk model rather than CVSS alone?
Vulnerability assessments
Hard
A.A CVSS 9.1 internal image builder blocked from networks and scheduled for decommissioning
B.A CVSS 9.8 isolated test server with no route to production and no usable credentials
C.A CVSS 8.1 internet-facing gateway with active exploitation and privileged cloud permissions
D.A CVSS 8.8 private workstation snapshot stored offline with no running compute instance
Correct Answer: A CVSS 8.1 internet-facing gateway with active exploitation and privileged cloud permissions
Explanation:
Active exploitation, external reachability, and privileged permissions create higher practical risk than a larger CVSS score on isolated or inactive assets.
Incorrect! Try again.
57Container workloads often terminate before a scheduled scanner can inspect them. Which assessment design best minimizes this visibility gap?
Vulnerability assessments
Hard
A.Increase monthly network-scan duration so more container address ranges are eventually tested
B.Scan only long-running nodes because containers inherit all vulnerability properties from hosts
C.Retain terminated container logs and infer package vulnerabilities solely from application errors
D.Scan build artifacts, enforce admission policy, and add runtime inventory for deployed instances
Correct Answer: Scan build artifacts, enforce admission policy, and add runtime inventory for deployed instances
Explanation:
Combining predeployment artifact scanning, admission enforcement, and runtime inventory covers both short-lived workloads and differences between images and deployed instances.
Incorrect! Try again.
58An authenticated scanner reports that a managed database is fully patched, but the service remains publicly reachable with weak authentication settings. What conclusion is most accurate?
Vulnerability assessments
Hard
A.The weak authentication setting is outside vulnerability management because it is not a software defect
B.The database is acceptably secure because authenticated scanning has verified its installed patch level
C.The public endpoint is irrelevant because managed database patching is performed by the cloud provider
D.Patch status alone is insufficient; configuration, identity, exposure, and control-plane assessments are also required
Correct Answer: Patch status alone is insufficient; configuration, identity, exposure, and control-plane assessments are also required
Explanation:
Cloud risk includes misconfiguration, excessive exposure, and weak identity controls. Vulnerability assessment must extend beyond missing software patches.
Incorrect! Try again.
59A security graph shows that a low-privilege developer can modify a build script, the build runner can assume a deployment role, and that role can alter production identity policies. Which remediation most directly breaks the attack path with minimal operational impact?
Proactive security posture
Hard
A.Prevent untrusted script changes from executing under the deployment role's trust relationship
B.Increase production log retention so modifications to identity policies remain available for investigation
C.Add another vulnerability scanner to the production network to identify exposed software services
D.Patch developer workstations more frequently to reduce the likelihood of initial account compromise
Correct Answer: Prevent untrusted script changes from executing under the deployment role's trust relationship
Explanation:
Breaking the trust link between modifiable build content and privileged role assumption removes the path to production while targeting the specific privilege-escalation mechanism.
Incorrect! Try again.
60A cloud security team wants to test whether leaked workload credentials can be detected and contained before an attacker reaches sensitive storage. Which exercise best evaluates the complete defensive capability?
Proactive security posture
Hard
A.Review the written incident-response plan and confirm that credential compromise appears as a scenario
B.Rotate all workload credentials without warning and measure how quickly application owners report failures
C.Execute a vulnerability scan against the workload and close every finding with a critical severity rating
D.Run an authorized purple-team scenario with injected credentials, monitored escalation, and containment objectives
Correct Answer: Run an authorized purple-team scenario with injected credentials, monitored escalation, and containment objectives
Explanation:
A controlled purple-team exercise validates telemetry, detection logic, escalation analysis, response coordination, and containment against a realistic attack sequence.
Incorrect! Try again.
Did this save you a night before the exam?
LPU Notes is free, and it stays free. Ads cover part of the server bill.
The rest comes out of a student's own pocket: the domain, the storage,
and keeping the site up through the weeks everyone needs it at once.
The payment button didn't load. An ad blocker or a filtered network is the usual reason.
to try again.
Nothing here is ever locked, and nothing unlocks. Chip in only if it was worth it.
What it pays for →