Each question below shows the correct answer with a full explanation. Use these to build conceptual understanding before attempting a timed quiz.
Cloud SecurityEasy
Q1. What is the shared responsibility model in cloud security?
- A.Both the provider and customer share responsibility for different aspects of security✓ Correct
- B.Only the customer is responsible for all security measures including infrastructure
- C.The cloud provider is solely responsible for everything including customer data
- D.No one is responsible for implementing security controls in cloud environments
Explanation
The provider secures the infrastructure while the customer secures their data, access, and configurations.
Report an error in this question
Cloud SecurityEasy
Q2. Why is data encryption important in cloud computing?
- A.To protect data confidentiality on shared infrastructure and during transmission✓ Correct
- B.To organize files better with structured directory layouts
- C.To make data load faster with improved performance speed
- D.To reduce storage costs through efficient data management
Explanation
Encryption protects data by ensuring it remains unreadable even if accessed by unauthorized parties.
Report an error in this question
Cloud SecurityEasy
Q3. What is a private cloud?
- A.A secret cloud that nobody uses or accesses at all
- B.Cloud infrastructure exclusively used by a single organization✓ Correct
- C.A specific type of weather and atmospheric phenomena
- D.A personal desktop computer used for individual tasks
Explanation
A private cloud is operated solely for one organization, offering greater control and security.
Report an error in this question
Cloud SecurityEasy
Q4. What is cloud computing?
- A.A weather forecasting system using satellite data analysis
- B.Storing files exclusively on your local desktop hard drive
- C.Delivering computing services like servers, storage, and software over the internet✓ Correct
- D.A type of external hard drive for portable data storage
Explanation
Cloud computing provides on-demand computing services delivered over the internet.
Report an error in this question
Cloud SecurityEasy
Q5. What are the three main cloud service models?
- A.Small, Medium, Large
- B.RAM, CPU, GPU
- C.IaaS, PaaS, SaaS✓ Correct
- D.HTTP, FTP, SMTP
Explanation
The three cloud service models are IaaS, PaaS, and SaaS.
Report an error in this question
Cloud SecurityEasy
Q6. What is a public cloud?
- A.Cloud infrastructure shared among multiple organizations over the internet✓ Correct
- B.A government-operated cloud for public sector agencies
- C.A cloud deployment visible to everyone on the internet
- D.A private physical server in an on-premises data center
Explanation
A public cloud provides shared computing resources managed by a cloud service provider.
Report an error in this question
Cloud SecurityEasy
Q7. What is a cloud access security broker (CASB)?
- A.A next-generation firewall for filtering network traffic flows
- B.A cloud provider offering infrastructure as a service
- C.A security tool between users and cloud services to enforce security policies✓ Correct
- D.An automated backup solution for enterprise data recovery needs
Explanation
A CASB enforces security policies between cloud consumers and providers.
Report an error in this question
Cloud SecurityEasy
Q8. What is the risk of misconfigured cloud storage?
- A.Faster data access speeds and improved system performance
- B.Accidental public exposure of sensitive data due to incorrect access permissions✓ Correct
- C.Better performance throughput for cloud-hosted applications
- D.Lower costs for cloud infrastructure resource consumption
Explanation
Misconfigured cloud storage can accidentally expose sensitive data to the public internet.
Report an error in this question
Cloud SecurityEasy
Q9. What is multi-tenancy in cloud computing?
- A.Multiple users connected to one physical computer terminal for shared access
- B.Having multiple user accounts on different cloud services for various purposes
- C.A cloud computing platform designed for hosting distributed enterprise workloads
- D.Multiple customers sharing physical infrastructure while data remains logically isolated✓ Correct
Explanation
Multi-tenancy means multiple customers share infrastructure with logical isolation ensuring data privacy.
Report an error in this question
Cloud SecurityMedium
Q10. What is the purpose of cloud audit logging?
- A.To record all activities and API calls for security monitoring and compliance✓ Correct
- B.To manage and administer user accounts and access rights
- C.To add computational overhead slowing the system and management
- D.To increase storage usage for expanded data capacity
Explanation
Cloud audit logs record all API calls and activities for monitoring and compliance.
Report an error in this question
Cloud SecurityMedium
Q11. What is DLP in cloud environments?
- A.Encrypting all data using symmetric cipher algorithm keys
- B.Compressing data files for reduced storage space consumption
- C.Creating redundant copies of data for backup recovery
- D.Technologies preventing sensitive data from being inappropriately shared or exposed✓ Correct
Explanation
Cloud DLP prevents unauthorized sharing or exposure of sensitive data.
Report an error in this question
Cloud SecurityMedium
Q12. What is server-side encryption in cloud storage?
- A.The cloud provider encrypts data at rest on the server before storing it✓ Correct
- B.Encrypting data on the client device before transmission
- C.A next-generation firewall for filtering network traffic flows
- D.A compression method for reducing cloud storage data sizes
Explanation
Server-side encryption means the provider encrypts data before storing it and decrypts it when accessed.
Report an error in this question
Cloud SecurityMedium
Q13. What is cloud security posture management (CSPM)?
- A.A standard software application used for routine enterprise computing operations
- B.A cloud infrastructure provider offering a range of core computing service options
- C.An automated solution monitoring cloud infrastructure for misconfigurations and compliance violations✓ Correct
- D.A cloud storage manager designed for organizing and managing hosted data resources
Explanation
CSPM continuously monitors cloud configurations against security best practices.
Report an error in this question
Cloud SecurityMedium
Q14. What is cloud workload protection?
- A.A backup solution for creating redundant data recovery copies
- B.A load balancing technique for distributing network traffic used in enterprise computing environments
- C.Security solutions protecting workloads including VMs, containers, and serverless functions✓ Correct
- D.Physical security of data center server hardware infrastructure
Explanation
Cloud workload protection secures workloads across cloud environments.
Report an error in this question
Cloud SecurityEasy
Q15. What is IAM in cloud security?
- A.A framework for managing digital identities and controlling user access to cloud resources✓ Correct
- B.A social media feature for managing online profile settings
- C.A file management system for organizing stored documents used in enterprise computing environments
- D.An email service for sending and receiving electronic messages
Explanation
Cloud IAM manages user identities and access permissions for cloud resources.
Report an error in this question
Cloud SecurityMedium
Q16. What is the difference between IaaS, PaaS, and SaaS security responsibilities?
- A.Customer always manages everything in every cloud model
- B.Security is not needed in any cloud computing environment for modern enterprise security environments
- C.In IaaS customer manages most; in PaaS provider manages more; in SaaS provider manages most✓ Correct
- D.Provider manages everything in all cloud service models
Explanation
Security responsibility shifts from customer (IaaS) to provider (SaaS) across service models.
Report an error in this question
Cloud SecurityMedium
Q17. What is a virtual private cloud (VPC)?
- A.A logically isolated section of public cloud where resources launch in a customer-defined virtual network✓ Correct
- B.A physical hardware component used in computing infrastructure
- C.A virtual private network encrypted tunnel connection used in enterprise computing environments
- D.A physical security measure for protecting building infrastructure
Explanation
A VPC provides a logically isolated virtual network within the public cloud.
Report an error in this question
Cloud SecurityHard
Q18. What is the NIST Cloud Computing Reference Architecture?
- A.A framework defining five major actors and their roles in cloud computing✓ Correct
- B.A cloud provider offering infrastructure as a service
- C.A security tool for scanning and detecting vulnerabilities
- D.A programming standard for writing cloud application code
Explanation
The NIST architecture defines cloud consumer, provider, auditor, broker, and carrier roles.
Report an error in this question
Cloud SecurityMedium
Q19. What is container security in cloud environments?
- A.An automated backup solution designed for enterprise data recovery needs and processes
- B.Protecting containerized apps through image scanning, runtime protection, and secure orchestration✓ Correct
- C.Securing physical shipping containers during transportation across global supply chains
- D.A physical security measure designed for protecting building infrastructure and premises
Explanation
Container security involves securing images, runtime environments, and orchestration platforms.
Report an error in this question
Cloud SecurityMedium
Q20. What are cloud security groups?
- A.User groups for managing organizational access permissions
- B.Social media groups for enterprise team communication
- C.A type of cloud storage for archiving large data volumes
- D.Virtual firewalls controlling inbound and outbound traffic to cloud resources✓ Correct
Explanation
Cloud security groups act as virtual firewalls controlling traffic based on defined rules.
Report an error in this question
Cloud SecurityHard
Q21. What is the blast radius concept in cloud security?
- A.A network speed measurement using bandwidth throughput used in enterprise computing environments
- B.The potential scope of damage if a security component is compromised, minimized through segmentation✓ Correct
- C.A storage capacity metric for measuring disk volume sizes used in enterprise computing environments
- D.A physical security measure for protecting building infrastructure
Explanation
Blast radius should be minimized through segmentation, least privilege, and workload isolation.
Report an error in this question
Cloud SecurityHard
Q22. What is cloud infrastructure entitlements management (CIEM)?
- A.Managing cloud storage volumes and tracking data capacity limits across regions
- B.Creating and provisioning new cloud user accounts across multiple environments
- C.Managing cloud billing and implementing cost optimization strategies for budgets
- D.Detecting and remediating excessive or unused permissions across multi-cloud environments✓ Correct
Explanation
CIEM identifies over-privileged identities and unused entitlements to enforce least privilege.
Report an error in this question
Cloud SecurityHard
Q23. What is CSA STAR certification?
- A.An astronomy certification for studying celestial objects used in enterprise computing environments
- B.A web browser application for accessing internet-hosted content
- C.A movie rating classification for content age suitability used in enterprise computing environments
- D.A third-party assessment of a cloud provider's security posture based on the Cloud Controls Matrix✓ Correct
Explanation
CSA STAR documents security controls of cloud providers through third-party audits.
Report an error in this question
Cloud SecurityHard
Q24. What is cloud key management service (KMS)?
- A.A managed service for creating and managing cryptographic keys for cloud data encryption✓ Correct
- B.A music streaming service platform for audio content used in enterprise computing environments
- C.A file management tool for organizing cloud storage resources
- D.A network routing service for directing cloud data traffic
Explanation
Cloud KMS provides centralized management of cryptographic keys with hardware security module backing.
Report an error in this question
Cloud SecurityHard
Q25. What is CNAPP?
- A.A web development framework designed for building scalable application frontend interfaces
- B.An integrated security platform combining CSPM, CWPP, and application security for cloud-native apps✓ Correct
- C.A mobile application store platform for downloading and distributing software packages
- D.A cloud computing platform used for hosting and managing distributed enterprise workloads
Explanation
CNAPP integrates posture management, workload protection, and app security for cloud-native applications.
Report an error in this question
Cloud SecurityMedium
Q26. What is least privilege in cloud IAM?
- A.Using shared credentials for all users in the environment
- B.Granting only the minimum permissions necessary for specific tasks✓ Correct
- C.Completely blocking all access to cloud resources
- D.Giving everyone administrator access to all resources
Explanation
Least privilege means assigning only the minimum necessary permissions to users and services.
Report an error in this question
Cloud SecurityHard
Q27. What is a confused deputy problem in cloud security?
- A.A confused employee who cannot follow security procedures used in enterprise computing environments
- B.A next-generation firewall for filtering network traffic flows
- C.A privilege escalation where a trusted service is tricked into performing unauthorized actions✓ Correct
- D.A DNS issue causing incorrect domain name resolution used in enterprise computing environments
Explanation
The confused deputy problem occurs when a service with elevated permissions is manipulated for unauthorized actions.
Report an error in this question
Cloud SecurityHard
Q28. What are the security implications of serverless computing?
- A.No security is needed because there are no significant threats regardless of the deployment context or scenario
- B.This is completely secure by default without configuration across computing environments
- C.Same security profile as traditional server hosting with no meaningful distinction between them
- D.Reduced OS attack surface but increased function-level risks including injection and insecure dependencies✓ Correct
Explanation
Serverless reduces infrastructure management but introduces function-level injection and dependency risks.
Report an error in this question
Cloud SecurityHard
Q29. What are immutable infrastructure security benefits?
- A.There are no security benefits from this approach regardless of the deployment context or scenario
- B.Faster server performance through hardware optimization
- C.Permanent servers that never change with no security benefit regardless of the deployment context or scenario
- D.Servers are never modified after deployment, reducing configuration drift and persistent threats✓ Correct
Explanation
Immutable infrastructure eliminates configuration drift and prevents persistent malware.
Report an error in this question
Cloud SecurityHard
Q30. What is the security challenge of multi-cloud environments?
- A.Managing consistent security policies and visibility across multiple providers with different tools✓ Correct
- B.Multi-cloud eliminates all security risks through redundancy
- C.There are no challenges with this approach at all in any deployment scenario or context
- D.Multi-cloud is inherently more secure than single-cloud
Explanation
Multi-cloud creates challenges in maintaining consistent security policies and unified visibility.
Report an error in this question