HomeSubjectsUniversityBlogAbout

Cloud Security

Topic in Cyber Security

210 total MCQsShowing 30 with explanations10 Easy10 Medium10 Hard

About This Topic

Cloud security is the set of policies, controls and technologies used to protect data, applications and infrastructure hosted on cloud platforms. The shared responsibility model is the anchor concept, since the split between provider and customer changes across IaaS, PaaS and SaaS. Questions also cover identity and access management, virtual private clouds and security groups, encryption with key management services, and the danger of misconfigured storage buckets. Tool-oriented items name CSPM, CASB and CWPP, while governance items mention CSA STAR, landing zones and multi-account setups where cross-account access can be abused. Deployment models and multi-tenancy risks round it out.

Below are 30 practice questions from a pool of 210 Cloud Security MCQs, one of 16 topics in Cyber Security. Each shows the correct answer with an explanation; when you are ready, take a timed quiz to test recall under exam conditions.

Practice Questions

Each question below shows the correct answer with a full explanation. Use these to build conceptual understanding before attempting a timed quiz.

Cloud SecurityEasy

Q1. What is the shared responsibility model in cloud security?

  1. A.Both the provider and customer share responsibility for different aspects of security✓ Correct
  2. B.Only the customer is responsible for all security measures including infrastructure
  3. C.The cloud provider is solely responsible for everything including customer data
  4. D.No one is responsible for implementing security controls in cloud environments

Explanation

The provider secures the infrastructure while the customer secures their data, access, and configurations.

Report an error in this question

Cloud SecurityEasy

Q2. Why is data encryption important in cloud computing?

  1. A.To protect data confidentiality on shared infrastructure and during transmission✓ Correct
  2. B.To organize files better with structured directory layouts
  3. C.To make data load faster with improved performance speed
  4. D.To reduce storage costs through efficient data management

Explanation

Encryption protects data by ensuring it remains unreadable even if accessed by unauthorized parties.

Report an error in this question

Cloud SecurityEasy

Q3. What is a private cloud?

  1. A.A secret cloud that nobody uses or accesses at all
  2. B.Cloud infrastructure exclusively used by a single organization✓ Correct
  3. C.A specific type of weather and atmospheric phenomena
  4. D.A personal desktop computer used for individual tasks

Explanation

A private cloud is operated solely for one organization, offering greater control and security.

Report an error in this question

Cloud SecurityEasy

Q4. What is cloud computing?

  1. A.A weather forecasting system using satellite data analysis
  2. B.Storing files exclusively on your local desktop hard drive
  3. C.Delivering computing services like servers, storage, and software over the internet✓ Correct
  4. D.A type of external hard drive for portable data storage

Explanation

Cloud computing provides on-demand computing services delivered over the internet.

Report an error in this question

Cloud SecurityEasy

Q5. What are the three main cloud service models?

  1. A.Small, Medium, Large
  2. B.RAM, CPU, GPU
  3. C.IaaS, PaaS, SaaS✓ Correct
  4. D.HTTP, FTP, SMTP

Explanation

The three cloud service models are IaaS, PaaS, and SaaS.

Report an error in this question

Cloud SecurityEasy

Q6. What is a public cloud?

  1. A.Cloud infrastructure shared among multiple organizations over the internet✓ Correct
  2. B.A government-operated cloud for public sector agencies
  3. C.A cloud deployment visible to everyone on the internet
  4. D.A private physical server in an on-premises data center

Explanation

A public cloud provides shared computing resources managed by a cloud service provider.

Report an error in this question

Cloud SecurityEasy

Q7. What is a cloud access security broker (CASB)?

  1. A.A next-generation firewall for filtering network traffic flows
  2. B.A cloud provider offering infrastructure as a service
  3. C.A security tool between users and cloud services to enforce security policies✓ Correct
  4. D.An automated backup solution for enterprise data recovery needs

Explanation

A CASB enforces security policies between cloud consumers and providers.

Report an error in this question

Cloud SecurityEasy

Q8. What is the risk of misconfigured cloud storage?

  1. A.Faster data access speeds and improved system performance
  2. B.Accidental public exposure of sensitive data due to incorrect access permissions✓ Correct
  3. C.Better performance throughput for cloud-hosted applications
  4. D.Lower costs for cloud infrastructure resource consumption

Explanation

Misconfigured cloud storage can accidentally expose sensitive data to the public internet.

Report an error in this question

Cloud SecurityEasy

Q9. What is multi-tenancy in cloud computing?

  1. A.Multiple users connected to one physical computer terminal for shared access
  2. B.Having multiple user accounts on different cloud services for various purposes
  3. C.A cloud computing platform designed for hosting distributed enterprise workloads
  4. D.Multiple customers sharing physical infrastructure while data remains logically isolated✓ Correct

Explanation

Multi-tenancy means multiple customers share infrastructure with logical isolation ensuring data privacy.

Report an error in this question

Cloud SecurityMedium

Q10. What is the purpose of cloud audit logging?

  1. A.To record all activities and API calls for security monitoring and compliance✓ Correct
  2. B.To manage and administer user accounts and access rights
  3. C.To add computational overhead slowing the system and management
  4. D.To increase storage usage for expanded data capacity

Explanation

Cloud audit logs record all API calls and activities for monitoring and compliance.

Report an error in this question

Cloud SecurityMedium

Q11. What is DLP in cloud environments?

  1. A.Encrypting all data using symmetric cipher algorithm keys
  2. B.Compressing data files for reduced storage space consumption
  3. C.Creating redundant copies of data for backup recovery
  4. D.Technologies preventing sensitive data from being inappropriately shared or exposed✓ Correct

Explanation

Cloud DLP prevents unauthorized sharing or exposure of sensitive data.

Report an error in this question

Cloud SecurityMedium

Q12. What is server-side encryption in cloud storage?

  1. A.The cloud provider encrypts data at rest on the server before storing it✓ Correct
  2. B.Encrypting data on the client device before transmission
  3. C.A next-generation firewall for filtering network traffic flows
  4. D.A compression method for reducing cloud storage data sizes

Explanation

Server-side encryption means the provider encrypts data before storing it and decrypts it when accessed.

Report an error in this question

Cloud SecurityMedium

Q13. What is cloud security posture management (CSPM)?

  1. A.A standard software application used for routine enterprise computing operations
  2. B.A cloud infrastructure provider offering a range of core computing service options
  3. C.An automated solution monitoring cloud infrastructure for misconfigurations and compliance violations✓ Correct
  4. D.A cloud storage manager designed for organizing and managing hosted data resources

Explanation

CSPM continuously monitors cloud configurations against security best practices.

Report an error in this question

Cloud SecurityMedium

Q14. What is cloud workload protection?

  1. A.A backup solution for creating redundant data recovery copies
  2. B.A load balancing technique for distributing network traffic used in enterprise computing environments
  3. C.Security solutions protecting workloads including VMs, containers, and serverless functions✓ Correct
  4. D.Physical security of data center server hardware infrastructure

Explanation

Cloud workload protection secures workloads across cloud environments.

Report an error in this question

Cloud SecurityEasy

Q15. What is IAM in cloud security?

  1. A.A framework for managing digital identities and controlling user access to cloud resources✓ Correct
  2. B.A social media feature for managing online profile settings
  3. C.A file management system for organizing stored documents used in enterprise computing environments
  4. D.An email service for sending and receiving electronic messages

Explanation

Cloud IAM manages user identities and access permissions for cloud resources.

Report an error in this question

Cloud SecurityMedium

Q16. What is the difference between IaaS, PaaS, and SaaS security responsibilities?

  1. A.Customer always manages everything in every cloud model
  2. B.Security is not needed in any cloud computing environment for modern enterprise security environments
  3. C.In IaaS customer manages most; in PaaS provider manages more; in SaaS provider manages most✓ Correct
  4. D.Provider manages everything in all cloud service models

Explanation

Security responsibility shifts from customer (IaaS) to provider (SaaS) across service models.

Report an error in this question

Cloud SecurityMedium

Q17. What is a virtual private cloud (VPC)?

  1. A.A logically isolated section of public cloud where resources launch in a customer-defined virtual network✓ Correct
  2. B.A physical hardware component used in computing infrastructure
  3. C.A virtual private network encrypted tunnel connection used in enterprise computing environments
  4. D.A physical security measure for protecting building infrastructure

Explanation

A VPC provides a logically isolated virtual network within the public cloud.

Report an error in this question

Cloud SecurityHard

Q18. What is the NIST Cloud Computing Reference Architecture?

  1. A.A framework defining five major actors and their roles in cloud computing✓ Correct
  2. B.A cloud provider offering infrastructure as a service
  3. C.A security tool for scanning and detecting vulnerabilities
  4. D.A programming standard for writing cloud application code

Explanation

The NIST architecture defines cloud consumer, provider, auditor, broker, and carrier roles.

Report an error in this question

Cloud SecurityMedium

Q19. What is container security in cloud environments?

  1. A.An automated backup solution designed for enterprise data recovery needs and processes
  2. B.Protecting containerized apps through image scanning, runtime protection, and secure orchestration✓ Correct
  3. C.Securing physical shipping containers during transportation across global supply chains
  4. D.A physical security measure designed for protecting building infrastructure and premises

Explanation

Container security involves securing images, runtime environments, and orchestration platforms.

Report an error in this question

Cloud SecurityMedium

Q20. What are cloud security groups?

  1. A.User groups for managing organizational access permissions
  2. B.Social media groups for enterprise team communication
  3. C.A type of cloud storage for archiving large data volumes
  4. D.Virtual firewalls controlling inbound and outbound traffic to cloud resources✓ Correct

Explanation

Cloud security groups act as virtual firewalls controlling traffic based on defined rules.

Report an error in this question

Cloud SecurityHard

Q21. What is the blast radius concept in cloud security?

  1. A.A network speed measurement using bandwidth throughput used in enterprise computing environments
  2. B.The potential scope of damage if a security component is compromised, minimized through segmentation✓ Correct
  3. C.A storage capacity metric for measuring disk volume sizes used in enterprise computing environments
  4. D.A physical security measure for protecting building infrastructure

Explanation

Blast radius should be minimized through segmentation, least privilege, and workload isolation.

Report an error in this question

Cloud SecurityHard

Q22. What is cloud infrastructure entitlements management (CIEM)?

  1. A.Managing cloud storage volumes and tracking data capacity limits across regions
  2. B.Creating and provisioning new cloud user accounts across multiple environments
  3. C.Managing cloud billing and implementing cost optimization strategies for budgets
  4. D.Detecting and remediating excessive or unused permissions across multi-cloud environments✓ Correct

Explanation

CIEM identifies over-privileged identities and unused entitlements to enforce least privilege.

Report an error in this question

Cloud SecurityHard

Q23. What is CSA STAR certification?

  1. A.An astronomy certification for studying celestial objects used in enterprise computing environments
  2. B.A web browser application for accessing internet-hosted content
  3. C.A movie rating classification for content age suitability used in enterprise computing environments
  4. D.A third-party assessment of a cloud provider's security posture based on the Cloud Controls Matrix✓ Correct

Explanation

CSA STAR documents security controls of cloud providers through third-party audits.

Report an error in this question

Cloud SecurityHard

Q24. What is cloud key management service (KMS)?

  1. A.A managed service for creating and managing cryptographic keys for cloud data encryption✓ Correct
  2. B.A music streaming service platform for audio content used in enterprise computing environments
  3. C.A file management tool for organizing cloud storage resources
  4. D.A network routing service for directing cloud data traffic

Explanation

Cloud KMS provides centralized management of cryptographic keys with hardware security module backing.

Report an error in this question

Cloud SecurityHard

Q25. What is CNAPP?

  1. A.A web development framework designed for building scalable application frontend interfaces
  2. B.An integrated security platform combining CSPM, CWPP, and application security for cloud-native apps✓ Correct
  3. C.A mobile application store platform for downloading and distributing software packages
  4. D.A cloud computing platform used for hosting and managing distributed enterprise workloads

Explanation

CNAPP integrates posture management, workload protection, and app security for cloud-native applications.

Report an error in this question

Cloud SecurityMedium

Q26. What is least privilege in cloud IAM?

  1. A.Using shared credentials for all users in the environment
  2. B.Granting only the minimum permissions necessary for specific tasks✓ Correct
  3. C.Completely blocking all access to cloud resources
  4. D.Giving everyone administrator access to all resources

Explanation

Least privilege means assigning only the minimum necessary permissions to users and services.

Report an error in this question

Cloud SecurityHard

Q27. What is a confused deputy problem in cloud security?

  1. A.A confused employee who cannot follow security procedures used in enterprise computing environments
  2. B.A next-generation firewall for filtering network traffic flows
  3. C.A privilege escalation where a trusted service is tricked into performing unauthorized actions✓ Correct
  4. D.A DNS issue causing incorrect domain name resolution used in enterprise computing environments

Explanation

The confused deputy problem occurs when a service with elevated permissions is manipulated for unauthorized actions.

Report an error in this question

Cloud SecurityHard

Q28. What are the security implications of serverless computing?

  1. A.No security is needed because there are no significant threats regardless of the deployment context or scenario
  2. B.This is completely secure by default without configuration across computing environments
  3. C.Same security profile as traditional server hosting with no meaningful distinction between them
  4. D.Reduced OS attack surface but increased function-level risks including injection and insecure dependencies✓ Correct

Explanation

Serverless reduces infrastructure management but introduces function-level injection and dependency risks.

Report an error in this question

Cloud SecurityHard

Q29. What are immutable infrastructure security benefits?

  1. A.There are no security benefits from this approach regardless of the deployment context or scenario
  2. B.Faster server performance through hardware optimization
  3. C.Permanent servers that never change with no security benefit regardless of the deployment context or scenario
  4. D.Servers are never modified after deployment, reducing configuration drift and persistent threats✓ Correct

Explanation

Immutable infrastructure eliminates configuration drift and prevents persistent malware.

Report an error in this question

Cloud SecurityHard

Q30. What is the security challenge of multi-cloud environments?

  1. A.Managing consistent security policies and visibility across multiple providers with different tools✓ Correct
  2. B.Multi-cloud eliminates all security risks through redundancy
  3. C.There are no challenges with this approach at all in any deployment scenario or context
  4. D.Multi-cloud is inherently more secure than single-cloud

Explanation

Multi-cloud creates challenges in maintaining consistent security policies and unified visibility.

Report an error in this question

Ready to test yourself on Cloud Security?

Take a timed quiz drawn from 210+ questions on this topic. No signup required — your progress saves in your browser.

Start Cloud Security Quiz