Unit 6: Emerging Trends and Best Practices in Cloud Security - Practice Quiz

INT328 — Network Virtualization And Cloud Security 60 Questions
0 Correct 0 Wrong 60 Left
0/60

1 Which security model assumes that no user or device should be trusted automatically?

Latest trends in cloud security Easy
A. Local Trust
B. Shared Hosting
C. Zero Trust
D. Open Access

2 Which recent cloud security trend focuses on protecting applications throughout their development lifecycle?

Latest trends in cloud security Easy
A. Data caching
B. DevSecOps
C. Server scaling
D. Load balancing

3 What does a cloud-native security approach primarily protect?

Latest trends in cloud security Easy
A. Desktop wallpapers
B. Physical notebooks
C. Cloud-based applications
D. Printed documents

4 How can artificial intelligence help improve cloud security?

Artificial intelligence in cloud security Easy
A. By increasing screen brightness
B. By detecting unusual activity
C. By replacing network cables
D. By reducing storage capacity

5 What type of data can an AI security system analyze to identify possible cloud attacks?

Artificial intelligence in cloud security Easy
A. Monitor color settings
B. Network traffic patterns
C. Document page margins
D. Keyboard layout choices

6 Which task can AI automate in a cloud security system?

Artificial intelligence in cloud security Easy
A. Cable manufacturing
B. Office scheduling
C. Hardware painting
D. Threat detection

7 Where does edge computing process data?

Edge computing Easy
A. Only in a central cloud
B. Only in an offline archive
C. Near the data source
D. Inside a backup facility

8 What is a major benefit of edge computing?

Edge computing Easy
A. Longer response delays
B. Higher network dependence
C. Slower device communication
D. Lower processing latency

9 Why must edge devices be secured?

Edge computing Easy
A. They always operate without data
B. They cannot connect to networks
C. They may handle sensitive data
D. They replace all cloud servers

10 Quantum cryptography is based primarily on principles from which field?

Quantum cryptography Easy
A. Database design
B. Classical mechanics
C. Quantum mechanics
D. Civil engineering

11 What is the main purpose of quantum key distribution?

Quantum cryptography Easy
A. To compress cloud files quickly
B. To exchange encryption keys securely
C. To create user interfaces
D. To increase processor speed

12 What may happen when an attacker observes information in a quantum communication channel?

Quantum cryptography Easy
A. The network speed may double
B. The storage size may increase
C. The quantum state may change
D. The cloud account may close

13 Which practice helps secure a newly deployed cloud service?

Secure cloud deployment Easy
A. Allowing unrestricted access
B. Changing default credentials
C. Sharing administrator passwords
D. Disabling security updates

14 Which access principle should be used during secure cloud deployment?

Secure cloud deployment Easy
A. Unlimited privilege
B. Least privilege
C. Permanent privilege
D. Anonymous privilege

15 What protects sensitive cloud data from being easily read if it is intercepted?

Secure cloud deployment Easy
A. Compression
B. Encryption
C. Indexing
D. Replication

16 What is the main purpose of a regular cloud security audit?

Regular audits Easy
A. To review security controls
B. To organize office equipment
C. To design application logos
D. To increase display quality

17 How often should cloud security audits generally be performed?

Regular audits Easy
A. Only when users complain
B. Only after every attack
C. At planned regular intervals
D. Once before initial deployment

18 What is the primary goal of a vulnerability assessment?

Vulnerability assessments Easy
A. To purchase cloud storage
B. To identify security weaknesses
C. To create employee accounts
D. To improve screen resolution

19 What commonly happens after vulnerabilities are discovered?

Vulnerability assessments Easy
A. They are prioritized for remediation
B. They are published as passwords
C. They are converted into backups
D. They are ignored permanently

20 What does a proactive cloud security posture emphasize?

Proactive security posture Easy
A. Responding only after incidents
B. Ignoring low-risk warnings
C. Preventing threats before incidents
D. Removing all security monitoring

21 A company uses multiple cloud providers and wants one system to enforce consistent identity, logging, and policy controls across all environments. Which trend best addresses this requirement?

Latest trends in cloud security Medium
A. Multicloud security management
B. Cloud-native security platforms
C. Traditional perimeter firewalls
D. Local hardware encryption

22 A development team frequently deploys containers and serverless functions. Which security practice is most aligned with current cloud security trends?

Latest trends in cloud security Medium
A. Restricting all workloads to physical servers
B. Embedding security throughout the development pipeline
C. Testing security only after deployment
D. Disabling automated deployment tools

23 An organization wants to verify that users and devices are trusted for every cloud access request, even when they are inside the corporate network. Which approach should it adopt?

Latest trends in cloud security Medium
A. A shared administrator account
B. A larger network perimeter
C. A zero-trust security model
D. A permanent VPN connection

24 An AI security system detects that an employee's account suddenly accesses data from two distant countries within a few minutes. What capability is the system applying?

Artificial intelligence in cloud security Medium
A. Routine backup scheduling
B. Behavioral anomaly detection
C. Network address translation
D. Static password validation

25 A cloud security model is trained using historical incidents, but its alerts increase significantly after a major change in user behavior. What is the most appropriate response?

Artificial intelligence in cloud security Medium
A. Delete the historical training data
B. Disable all automated alerts
C. Grant broader access to users
D. Retrain and validate the model

26 An AI tool recommends isolating a production workload after detecting suspicious activity. What should a security analyst do before allowing automatic isolation?

Artificial intelligence in cloud security Medium
A. Remove the workload's audit records
B. Review the recommendation and its evidence
C. Approve every recommendation immediately
D. Ignore the recommendation permanently

27 A healthcare provider processes patient-monitoring data at edge locations to reduce latency. Which security control is especially important for these distributed sites?

Edge computing Medium
A. A single unchanging administrator password
B. Removing authentication from local devices
C. Disabling local system updates
D. Physical and remote device protection

28 An edge device continues collecting sensitive data when its connection to the central cloud is interrupted. Which design choice best reduces security risk?

Edge computing Medium
A. Apply local encryption and retention limits
B. Transmit data through an open wireless network
C. Disable all local access controls
D. Store data indefinitely on the device

29 A company deploys thousands of edge sensors from different manufacturers. Which approach best supports consistent security management?

Edge computing Medium
A. Allow each sensor to select its own credentials
B. Update sensors only after an incident
C. Use standardized secure onboarding procedures
D. Permit unrestricted communication between sensors

30 A financial institution is concerned that encrypted data captured today could be decrypted by future quantum computers. Which strategy best addresses this risk?

Quantum cryptography Medium
A. Reduce the length of encryption keys
B. Reuse existing session keys longer
C. Adopt quantum-resistant cryptographic algorithms
D. Publish encryption keys for verification

31 In quantum key distribution, an unauthorized party measures photons while attempting to intercept a key. What security property helps reveal the interception?

Quantum cryptography Medium
A. Network addresses hide the key
B. Measurement can disturb quantum states
C. Photons automatically duplicate themselves
D. Keys are stored in plain text

32 A cloud provider is planning a long-term migration to post-quantum security. Which preparation is most practical before replacing all current cryptographic systems?

Quantum cryptography Medium
A. Remove encryption from legacy systems
B. Use one key for every application
C. Inventory cryptographic dependencies
D. Wait until quantum attacks are confirmed

33 A team is deploying a cloud application that stores customer records. Which configuration most directly reduces unauthorized access?

Secure cloud deployment Medium
A. Public storage with a complex file name
B. Default permissions with rotating usernames
C. Private storage with least-privilege roles
D. Shared storage with anonymous read access

34 A deployment pipeline creates cloud resources from approved templates. A security engineer wants to prevent insecure configurations before deployment. Which control is most suitable?

Secure cloud deployment Medium
A. Manual review of production logs
B. Disabling version control for templates
C. Postponing configuration checks indefinitely
D. Infrastructure-as-code security scanning

35 During a cloud audit, an organization discovers that several inactive accounts still have administrative permissions. What should be done first?

Regular audits Medium
A. Export the accounts to a public report
B. Remove or disable unnecessary accounts
C. Create additional administrator accounts
D. Ignore the accounts until the next audit

36 A company wants its cloud audit findings to be useful for improving security over time. Which practice is most effective?

Regular audits Medium
A. Track findings through documented remediation
B. Record only successful control tests
C. Delete findings after management review
D. Perform audits without assigning owners

37 A vulnerability scanner reports a critical issue in a public-facing virtual machine. What factor should primarily influence remediation priority?

Vulnerability assessments Medium
A. The age of the scanning tool
B. The issue's risk and exposure
C. The virtual machine's display name
D. The number of installed applications

38 A scan identifies a vulnerability in a cloud service, but the service is protected by strict network controls and is not internet-facing. How should the result be handled?

Vulnerability assessments Medium
A. Ignore it because exposure is limited
B. Publish the vulnerability without verification
C. Immediately delete the entire cloud account
D. Assess context and plan appropriate remediation

39 A security team continuously monitors cloud configurations and automatically compares them with approved baselines. What security objective does this primarily support?

Proactive security posture Medium
A. Increasing the number of cloud regions
B. Detecting and correcting configuration drift
C. Replacing all incident response procedures
D. Eliminating the need for user training

40 A company conducts tabletop exercises for a possible cloud ransomware incident. Which benefit most directly supports a proactive security posture?

Proactive security posture Medium
A. Improving response readiness before an incident
B. Replacing encryption with faster networking
C. Reducing the need for system monitoring
D. Guaranteeing that attacks cannot occur

41 An enterprise operates Kubernetes clusters, serverless functions, and virtual machines across three cloud providers. Security teams receive thousands of isolated findings without knowing which findings form exploitable attack paths. Which modernization most directly addresses this problem?

Latest trends in cloud security Hard
A. Replace provider-native security services with a single perimeter firewall platform
B. Deploy separate signature-based IDS appliances within every cloud virtual network
C. Consolidate infrastructure logs into a centralized long-term archival storage account
D. Adopt a CNAPP that correlates identities, configurations, vulnerabilities, workloads, and attack paths

42 A multi-cloud organization is replacing network-location trust with identity-centric controls. Which design most closely implements a cloud-native Zero Trust model?

Latest trends in cloud security Hard
A. Grant access to cloud accounts after authenticating once through a centralized VPN
B. Grant access through long-lived service credentials restricted by source IP addresses
C. Grant access after continuously evaluating workload identity, device state, context, and policy
D. Grant access to all resources after a user enters the corporate private network

43 A behavioral model retrained from recent cloud telemetry gradually stops flagging a malicious API sequence because an attacker repeatedly injects similar low-volume events into the training stream. What is the most appropriate primary defense?

Artificial intelligence in cloud security Hard
A. Allow the model to retrain automatically whenever its alert volume falls below baseline
B. Use provenance-verified training data, poisoning detection, and independently validated model versions
C. Increase the model learning rate so that new API sequences are incorporated more quickly
D. Remove historical observations so that the model emphasizes current production behavior

44 An AI detector is evaluated under the cost function , where is the number of false negatives and is the number of false positives. Which operating point minimizes cost?

Artificial intelligence in cloud security Hard
A.
B.
C.
D.

45 A cloud anomaly model has stable test accuracy but produces increasing false positives after a major migration from virtual machines to serverless workloads. Which response best addresses the likely cause without weakening detection globally?

Artificial intelligence in cloud security Hard
A. Measure feature drift, segment by workload type, and retrain using validated serverless telemetry
B. Replace behavioral detection with static signatures derived from historical virtual-machine incidents
C. Raise one global anomaly threshold until the total alert count returns to its previous level
D. Suppress all alerts associated with newly created serverless functions for an initial period

46 Edge gateways must authorize safety-critical commands during intermittent disconnection from the central cloud. Which architecture best balances availability with bounded security risk?

Edge computing Hard
A. Cache administrator passwords locally and replay cloud authentication when connectivity returns
B. Use short-lived signed capabilities, locally cached policy, secure time, and deny-by-default expiry
C. Permit all previously observed commands until the gateway reconnects to the central policy engine
D. Disable authorization during outages while retaining encrypted logging for later cloud inspection

47 A cloud service must release decryption keys only to edge nodes running approved firmware and an untampered boot chain. Which mechanism most directly provides this assurance?

Edge computing Hard
A. Verify that the node communicates through an encrypted provider-managed network tunnel
B. Verify hardware-rooted remote-attestation evidence before issuing an ephemeral key
C. Verify that the node presents a certificate issued by the enterprise certificate authority
D. Verify that the node reports the expected operating-system version in its inventory record

48 Thousands of edge sensors contribute measurements to a cloud analytics service, but individual readings must remain hidden from both the network and the aggregator. The cloud needs only the sum of all readings. Which approach is most suitable?

Edge computing Hard
A. Apply deterministic encryption so identical individual measurements remain searchable in storage
B. Apply transport encryption and decrypt every individual measurement at the cloud load balancer
C. Apply secure aggregation so the cloud recovers the aggregate without individual measurements
D. Apply tokenization at the cloud gateway after each individual measurement has been received

49 Two data centers use quantum key distribution to generate symmetric keys. Why is an authenticated classical channel still required?

Quantum cryptography Hard
A. Without classical authentication, generated keys cannot be used by symmetric encryption algorithms
B. Without classical authentication, an active attacker can impersonate both QKD endpoints
C. Without classical authentication, quantum states cannot travel through an optical transmission medium
D. Without classical authentication, photon measurements cannot reveal interception-induced disturbances

50 An organization fears that adversaries are collecting encrypted traffic now for future quantum decryption. Which migration strategy provides the strongest practical transition for key establishment?

Quantum cryptography Hard
A. Increase RSA modulus sizes while retaining the same certificate and exchange protocols
B. Use a validated hybrid exchange combining classical and post-quantum shared secrets
C. Encrypt each session twice with independent AES-256 keys derived from classical RSA
D. Replace public-key exchange with reusable symmetric keys distributed through cloud storage

51 A production resource is manually modified after deployment, creating a difference from its reviewed Infrastructure as Code template. Which control most effectively prevents the modification from becoming a persistent hidden state?

Secure cloud deployment Hard
A. Continuously detect drift and reconcile or redeploy resources from the approved immutable definition
B. Permit emergency modifications if administrators document their intended changes in a ticket
C. Record administrator commands and review the activity during the next quarterly compliance meeting
D. Back up the modified resource state so the manual configuration can be restored after a failure

52 A Kubernetes deployment pipeline must prevent containers from reaching production if they are unsigned, request privileged execution, or contain critical exploitable packages. Where should enforcement primarily occur?

Secure cloud deployment Hard
A. At runtime using log analysis after the containers have started serving production traffic
B. At the registry using repository naming rules and periodic manual image-tag inspections
C. At admission using signed provenance, policy-as-code, and vulnerability decision criteria
D. At the network layer using ingress filtering and encrypted service-to-service communication

53 A microservice currently stores a long-lived cloud API key in an encrypted environment variable. Which redesign best reduces secret theft and rotation risk?

Secure cloud deployment Hard
A. Rotate the encrypted API key annually and inject it through a protected build pipeline
B. Use workload identity federation to obtain short-lived, narrowly scoped credentials
C. Store the API key in a private source repository restricted to deployment administrators
D. Split the API key across two environment variables reconstructed when the service starts

54 An auditor finds that storage encryption was enabled on the audit date, but the organization cannot prove it remained enabled throughout the year. Which evidence would best address the deficiency?

Regular audits Hard
A. Immutable time-stamped configuration history showing continuous control state and detected changes
B. A current asset inventory listing the storage service as subject to the encryption policy
C. A management statement confirming that encryption was intended to remain enabled all year
D. A screenshot of the encrypted storage settings captured during the auditor's final interview

55 A SaaS provider claims that all security controls are covered by the cloud infrastructure provider's compliance report. What should an auditor examine first?

Regular audits Hard
A. The infrastructure provider's total number of certifications and global data-center regions
B. The infrastructure provider's uptime history and publicly announced service-level objectives
C. The shared-responsibility mapping, complementary controls, service scope, and report exceptions
D. The SaaS provider's marketing description of encryption and high-availability capabilities

56 Four vulnerable assets require prioritization. Which should be remediated first when using an exposure-aware risk model rather than CVSS alone?

Vulnerability assessments Hard
A. A CVSS 9.1 internal image builder blocked from networks and scheduled for decommissioning
B. A CVSS 9.8 isolated test server with no route to production and no usable credentials
C. A CVSS 8.1 internet-facing gateway with active exploitation and privileged cloud permissions
D. A CVSS 8.8 private workstation snapshot stored offline with no running compute instance

57 Container workloads often terminate before a scheduled scanner can inspect them. Which assessment design best minimizes this visibility gap?

Vulnerability assessments Hard
A. Increase monthly network-scan duration so more container address ranges are eventually tested
B. Scan only long-running nodes because containers inherit all vulnerability properties from hosts
C. Retain terminated container logs and infer package vulnerabilities solely from application errors
D. Scan build artifacts, enforce admission policy, and add runtime inventory for deployed instances

58 An authenticated scanner reports that a managed database is fully patched, but the service remains publicly reachable with weak authentication settings. What conclusion is most accurate?

Vulnerability assessments Hard
A. The weak authentication setting is outside vulnerability management because it is not a software defect
B. The database is acceptably secure because authenticated scanning has verified its installed patch level
C. The public endpoint is irrelevant because managed database patching is performed by the cloud provider
D. Patch status alone is insufficient; configuration, identity, exposure, and control-plane assessments are also required

59 A security graph shows that a low-privilege developer can modify a build script, the build runner can assume a deployment role, and that role can alter production identity policies. Which remediation most directly breaks the attack path with minimal operational impact?

Proactive security posture Hard
A. Prevent untrusted script changes from executing under the deployment role's trust relationship
B. Increase production log retention so modifications to identity policies remain available for investigation
C. Add another vulnerability scanner to the production network to identify exposed software services
D. Patch developer workstations more frequently to reduce the likelihood of initial account compromise

60 A cloud security team wants to test whether leaked workload credentials can be detected and contained before an attacker reaches sensitive storage. Which exercise best evaluates the complete defensive capability?

Proactive security posture Hard
A. Review the written incident-response plan and confirm that credential compromise appears as a scenario
B. Rotate all workload credentials without warning and measure how quickly application owners report failures
C. Execute a vulnerability scan against the workload and close every finding with a critical severity rating
D. Run an authorized purple-team scenario with injected credentials, monitored escalation, and containment objectives