Be able to map a cloud security requirement to the right control: CASB for SaaS visibility and DLP, CWPP for workload and container protection, and a secrets manager for credentials. The key is separating SaaS, workload, and secrets use cases before answering.
Start practicing
Cloud Security — choose a session length
Free · No account required
Domain overview
Cloud Security is 15% of the 350-701 SCOR exam and covers securing SaaS, IaaS, and PaaS environments. Questions test CASB, cloud workload protection, secrets management, and shared responsibility, usually as scenario items asking you to select the correct Cisco or cloud-native control for a stated problem.
Exam objectives
Selecting a CASB to discover shadow IT SaaS usage and enforce DLP on cloud app data
Using secrets managers such as HashiCorp Vault or AWS Secrets Manager instead of hardcoded credentials
Applying cloud workload protection platforms to secure VMs, containers, and serverless workloads
Cisco Cloudlock/Cisco Umbrella and Secure Workload capabilities for cloud visibility and microsegmentation
Confusing CASB (SaaS visibility and DLP) with CWPP (workload threat protection) and choosing the wrong tool for the scenario.
Assuming the cloud provider secures everything; the shared responsibility model splits duties between provider and customer.
Storing secrets in environment variables or code and thinking that is secure; secrets managers are the expected answer.
Click any question to see the full explanation and answer options, or start a focused practice session above.
A company is moving its on-premises applications to AWS EC2 instances. According to the shared responsibility model, which of the following is the customer's responsibility?
2An organization uses multiple SaaS applications and wants to enforce data loss prevention (DLP) policies to prevent sensitive data from being shared externally. Which cloud security solution should be deployed?
3An organization wants to implement zero trust principles for cloud access. Which of the following is a key component of a zero trust architecture in the cloud?
4Which of the following is the primary function of a Cloud Security Posture Management (CSPM) tool?
5A company uses Cisco Umbrella to provide DNS-layer security. An employee tries to visit a website that is hosting malware, but the domain is not yet categorized. How does Umbrella handle this request?
6An organization is deploying containerized applications in a Kubernetes cluster on AWS EKS. They need to ensure that container images are scanned for vulnerabilities before deployment. Which approach aligns with DevSecOps best practices?
7A security team is implementing AWS WAF to protect a web application. They want to block requests that contain SQL injection patterns in the query string. Which AWS WAF component should be used?
8In the shared responsibility model for PaaS, which of the following is typically the customer's responsibility?
9A DevSecOps team is implementing secrets management for a cloud-native application. They want to avoid storing secrets in environment variables or code. Which solution should they use?
10An organization is adopting zero trust principles for cloud access. Which THREE measures are essential for implementing identity-centric security? (Choose three.)
11A company is using Azure and wants to enforce security compliance across their cloud resources. Which TWO services are part of CSPM (Cloud Security Posture Management) in Azure? (Choose two.)
12In the shared responsibility model for cloud services, which layer is the customer responsible for managing in an IaaS environment?
13A security team wants to gain visibility into Shadow IT usage of SaaS applications and enforce data loss prevention policies. Which cloud security solution should they deploy?
14An organization uses Cisco Umbrella to block malicious domains. Which layer does Umbrella primarily operate at to prevent connections before they are established?
15A company wants to ensure that no cloud workload has a public IP address attached to a network security policy that allows inbound SSH from the entire internet. Which Cisco security product can continuously monitor and alert on such misconfigurations?
16A DevSecOps team is integrating security into their CI/CD pipeline. They want to scan Terraform configuration files for misconfigurations before deployment. Which tool is specifically designed for that purpose?
17In the shared responsibility model for PaaS, which of the following is the customer responsible for?
18An organization uses Cisco Umbrella's Secure Internet Gateway (SIG). Which of the following sets of capabilities is typically included in a SIG solution?
19A cloud security architect is designing zero trust for a multi-cloud environment. Which principle is most critical?
20A security team wants to inspect SSL-encrypted traffic from users accessing SaaS applications through Cisco Umbrella. Which feature should they enable?
21Which cloud security control is specifically designed to protect workloads such as VMs and containers from threats?
22A company uses Azure and wants to restrict network traffic between subnets. Which Azure resource should they use?
23In a DevSecOps pipeline, a team wants to prevent secrets (e.g., API keys) from being stored in source code. Which approach is most effective?
24In the shared responsibility model for cloud security, which responsibility is the customer's in an IaaS deployment?
25A security team wants to gain visibility into shadow IT usage of SaaS applications and enforce DLP policies for data shared via cloud apps. Which cloud security solution should they deploy?
26An organization uses Cisco Umbrella to block malicious domains. The security team notices that some malware traffic bypasses DNS-layer blocking because the malware uses hardcoded IP addresses. Which Umbrella feature should be enabled to additionally inspect traffic at the IP layer?
27A DevOps team is building a CI/CD pipeline for a cloud-native application. They want to automatically check Terraform scripts for insecure configurations before deployment. Which tool should be integrated into the pipeline?
28An organization is adopting a zero-trust model for cloud access. Which component enforces conditional access policies based on user, device, location, and risk level in Azure AD?
29In the shared responsibility model, which is the customer's responsibility in a SaaS model?
30Which Cisco Umbrella feature provides off-network protection by intercepting DNS requests on a user's device?
31A security engineer is configuring Cisco Umbrella to block HTTPS traffic to malicious sites. However, they want to inspect SSL-encrypted traffic selectively to avoid breaking applications. Which Umbrella feature should they use?
32A company is moving workloads to Google Cloud and needs private connectivity between its on-premises data center and VPC without traversing the internet. Which service should be used?
33A security team is implementing DevSecOps practices. Which TWO actions should be taken to secure secrets (e.g., API keys, passwords) in a CI/CD pipeline? (Choose two.)
34A company is adopting a zero-trust security model for its cloud environment. Which THREE practices align with zero-trust principles? (Choose three.)
35A security engineer is designing cloud workload protection (CWPP) for a hybrid environment with VMs and containers. Which TWO capabilities should a CWPP solution provide? (Choose two.)
36In the shared responsibility model for cloud computing, which responsibility is managed by the customer in all service models (IaaS, PaaS, SaaS)?
37A security administrator wants to enforce a policy that blocks upload of sensitive data to unauthorized cloud applications. Which technology should be used to gain visibility and control over sanctioned and unsanctioned SaaS applications?
38An organization uses Cisco Umbrella to protect remote users. The security team notices that some malicious domains are not blocked because users are bypassing the DNS layer by using direct IP connections or non-DNS protocols. Which Cisco Umbrella feature should be enabled to inspect all traffic, including non-web traffic, and enforce policies regardless of DNS resolution?
39A company is deploying workloads in AWS and wants to ensure that the security groups are not overly permissive. They need to continuously monitor for misconfigurations and compare against the CIS AWS Foundations Benchmark. Which tool should be used?
40To enforce zero trust principles in a cloud environment, an administrator requires all access to cloud resources to be authenticated and authorized based on user identity and device health. Which Cisco Duo feature enables policies that consider conditions such as location, device compliance, and risk level?
41In a DevSecOps pipeline, a security engineer wants to automatically scan Infrastructure as Code (IaC) templates for security misconfigurations before deployment. Which tool is commonly used for static analysis of Terraform templates?
42A security team is implementing secure access for remote users connecting from untrusted networks. They want to enforce DNS-layer security even when users are off the corporate network. Which Cisco Umbrella feature should be deployed on the endpoints?
43In the shared responsibility model for PaaS, which component is the customer responsible for managing?
44A company uses multiple SaaS applications and wants to enforce data loss prevention (DLP) policies to prevent sensitive data from being shared externally. Which technology provides the ability to scan data in transit and at rest within these SaaS applications?
45A security engineer is configuring Cisco Umbrella Intelligent Proxy to selectively decrypt and inspect HTTPS traffic. The goal is to balance security and user privacy by only inspecting traffic to high-risk domains. How does Intelligent Proxy decide which traffic to inspect?
46A security team is implementing a DevSecOps pipeline for containerized applications. Which TWO of the following practices should be included to ensure container security?
47An organization is adopting zero trust principles for cloud access. Which THREE components should be implemented to enforce identity as the new perimeter?
48A company uses AWS and Azure and wants to protect its cloud workloads (VMs and containers) from threats. Which TWO technologies are specifically designed for workload protection in the cloud?
49In the shared responsibility model for cloud security, which of the following is the customer responsible for in an IaaS deployment?
50A company is using a SaaS application like Office 365. Which security responsibility falls on the customer according to the shared responsibility model?
51A security team wants to gain visibility into shadow IT usage of cloud applications and enforce data loss prevention policies. Which cloud security control should they deploy?
52An organization uses Cisco Umbrella to block malicious domains. What is the primary security benefit of DNS-layer security?
53A company is deploying Cisco Umbrella with the Intelligent Proxy feature. Under what condition does the Intelligent Proxy perform SSL decryption?
54In AWS, which resource acts as a stateful firewall at the instance level to control inbound and outbound traffic?
55A security architect is designing a zero-trust model for cloud access. Which of the following is a core principle of zero trust in the cloud?
56In a DevSecOps pipeline, which tool would be used to scan Infrastructure as Code (IaC) templates for security misconfigurations?
57A security engineer needs to prevent secrets (e.g., API keys) from being stored in code repositories. Which DevSecOps practice should be implemented?
58Which cloud workload protection platform (CWPP) capability is essential for protecting containerized applications?
59A security team is implementing CSPM to ensure cloud compliance. Which three checks would a CSPM tool typically perform? (Choose three.)
60Which two controls are considered part of a zero-trust architecture for cloud access? (Choose two.)
61A company uses a SaaS application for customer relationship management. In the cloud shared responsibility model, which security controls are the customer's primary responsibility?
62A security team wants to enforce data loss prevention (DLP) policies across multiple sanctioned cloud applications used by employees. Which cloud security solution is best suited for this task?
63A company uses Cisco Umbrella to protect remote users. They want to ensure that SSL-encrypted traffic to malicious websites is inspected, but without breaking compliance with privacy regulations. Which Umbrella feature should they enable?
64A cloud engineer is deploying a web application on AWS and needs to control inbound and outbound traffic at both the instance and subnet levels. Which two AWS security controls should they configure? (Select two.)
65A DevSecOps team is integrating security into their CI/CD pipeline. They want to scan infrastructure-as-code templates for misconfigurations and container images for vulnerabilities. Which two tools are appropriate? (Select two.)
66An organization is adopting a zero trust model for cloud access. Which three principles should be implemented? (Select three.)
67A security architect at a financial services firm is deploying a new multi-tier web application on AWS. The application runs on Amazon EC2 instances behind an Application Load Balancer and stores sensitive customer data in an Amazon RDS database. The security team wants to block common web exploits such as SQL injection and cross-site scripting at the edge before traffic reaches the EC2 instances, and they want to use a managed AWS service that integrates with AWS WAF. Which AWS service should the architect use to provide this protection?
68A security architect at a financial services company is deploying a new multi-tenant SaaS application on AWS. The application must encrypt sensitive customer data at rest using keys that the company generates and manages, but the company does not want to manage the underlying hardware security modules (HSMs). Which AWS service should be used to meet these requirements?
69A security team is using Cisco Umbrella to protect users accessing cloud applications. They want to enforce a policy that blocks access to unsanctioned cloud applications while allowing sanctioned ones, and they need to identify which cloud applications are in use. Which Cisco Umbrella feature should they use?
70A security architect is designing a cloud environment on Microsoft Azure and needs to protect outbound traffic from virtual machines to the internet. The organization requires that all outbound traffic be inspected by a next-generation firewall, even when the traffic is destined for arbitrary internet IP addresses. Which Azure-native solution should the architect implement?
71A security engineer is configuring Cisco Umbrella to enforce security policies for a remote workforce. The company wants to block access to newly seen domains that are less than 24 hours old, as these are often used in malicious campaigns. Which Umbrella feature should the engineer enable to achieve this?
72A cloud security team is using Amazon GuardDuty to monitor their AWS environment. They receive a finding indicating that an EC2 instance is communicating with a known cryptocurrency mining pool. Which action should the team take to automatically remediate this finding?
73A security administrator is implementing Cisco Cloudlock to protect data in a SaaS environment. The organization wants to detect and respond to sensitive data exposure in sanctioned cloud applications. Which TWO capabilities does Cisco Cloudlock provide to achieve this? (Choose two.)
74A security architect is designing a multi-account AWS environment for a financial services company. The company requires that all API activity across every account be centrally logged, retained for seven years, and protected from modification even by account administrators. Which combination of AWS services should the architect implement to meet these requirements?
75A company is migrating its on-premises web application to Google Cloud Platform (GCP). The security team wants to protect the application from common web exploits such as SQL injection and cross-site scripting. They also want to leverage Google's infrastructure for scaling and DDoS protection. Which GCP service should they implement?
76A cloud security engineer is configuring Cisco Umbrella to protect a branch office. The company wants to block access to known malicious domains and also wants visibility into which internal user or device made each request. The branch uses a Cisco router as the DNS forwarder for all endpoints. Which Umbrella component and configuration should the engineer deploy?
77A security team is deploying a multi-tier web application on AWS. They need to continuously monitor for misconfigured S3 buckets and overly permissive IAM policies, and receive alerts when deviations occur. Which Cisco solution should they implement to achieve this?
78A company is migrating its on-premises web application to AWS. The security team must ensure that only HTTP and HTTPS traffic from the internet reaches the application, while all other inbound ports are blocked. Which AWS feature should they configure to meet this requirement?
79A security team is evaluating Cisco Cloudlock to protect data stored in SaaS applications such as Microsoft 365 and Google Workspace. The team wants to understand which capabilities Cloudlock provides natively. (Choose two.)
80A security architect is designing a multi-cloud environment that includes AWS, Azure, and on-premises VMware vSphere. The organization wants a single, consistent security policy to be enforced across all workload locations, including east-west traffic between virtual machines. Which Cisco solution should the architect deploy to meet this requirement?
81A security architect is deploying a multicloud environment that spans AWS, Azure, and GCP. The organization requires a centralized, agentless solution that discovers all workloads, detects misconfigurations against CIS benchmarks, and provides a unified compliance dashboard across all three providers. Which Cisco solution best meets these requirements?
82A security architect is designing a solution to protect user access to SaaS applications. The organization wants to enforce data loss prevention policies, detect anomalous user behavior, and provide granular visibility into sanctioned and unsanctioned cloud apps. Which Cisco technology should be deployed?
83A security team is using Cisco Umbrella to protect users who access cloud applications. They want to enforce a policy that prevents users from uploading files containing credit card numbers to any unsanctioned cloud storage service, while still allowing uploads to approved services. Which Cisco Umbrella capability should they configure?
84A security architect is designing a cloud access security broker (CASB) deployment for a company that uses Microsoft 365 and Salesforce. The company wants to apply data loss prevention (DLP) policies to data at rest within these SaaS applications without installing endpoint agents, and it wants to maintain full visibility into which users are sharing files externally. Which CASB deployment mode should the architect choose?
85A company is migrating its customer-facing web application to Microsoft Azure. The security team must ensure that only HTTP and HTTPS traffic reaches the web tier from the internet and that no other inbound ports are exposed. Which Azure feature should they configure?
86A financial services company uses Cisco Umbrella to protect users accessing SaaS applications. The security team needs to block uploads of files containing personally identifiable information (PII) to unsanctioned cloud storage services while allowing uploads to approved services. Which Cisco Umbrella capability should be configured?
87A security operations team uses Cisco Secure Workload to protect a Kubernetes cluster running on Amazon EKS. They need to ensure that only approved container images are allowed to run, and that any attempt to run an unapproved image is blocked before the pod starts. Which Cisco Secure Workload capability should they implement?
88A security team is implementing a cloud access security broker (CASB) solution to gain visibility and control over SaaS application usage. Which two deployment modes are commonly supported by Cisco Cloudlock? (Choose two.)
89A security operations team is using Cisco Secure Cloud Analytics (formerly Stealthwatch Cloud) to monitor a hybrid cloud environment. They want to detect threats such as cryptomining and data exfiltration across AWS, Azure, and on-premises networks without deploying agents on every workload. Which statement describes how Cisco Secure Cloud Analytics achieves this?
90A company is migrating its on-premises web application to AWS. The security team wants to protect the application from common web exploits such as SQL injection and cross-site scripting, and also mitigate distributed denial-of-service (DDoS) attacks at the application layer. Which AWS service should they use in conjunction with AWS Shield?
91A cloud operations team is deploying a multi-tier application in Microsoft Azure. The security team wants to ensure that only HTTP and HTTPS traffic from the internet can reach the web tier, while the database tier should accept connections only from the web tier. They also want to log allowed and denied flows for auditing. Which Azure feature should they configure to meet these requirements?
92A security team is evaluating Cisco Cloudlock to protect data in a sanctioned SaaS environment. They want to understand which capabilities Cisco Cloudlock provides for data security in cloud applications. (Choose two.)
93A security team is deploying a web application in a public cloud. They need to protect it from common web exploits like SQL injection and cross-site scripting, and also mitigate bot attacks. Which Cisco cloud security solution provides these capabilities with minimal configuration and integrates with cloud-native load balancers?
94A security engineer is reviewing the shared responsibility model for a company that is using a SaaS-based email service. The company wants to understand which security controls they are responsible for managing. According to the shared responsibility model, which area is the customer's responsibility in a SaaS deployment?
Be able to map a cloud security requirement to the right control: CASB for SaaS visibility and DLP, CWPP for workload and container protection, and a secrets manager for credentials. The key is separating SaaS, workload, and secrets use cases before answering.
The Courseiva 350-701 question bank contains 94 questions in the Cloud Security domain, covering the 15% of the exam attributed to this domain in the official Cisco blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Cloud Security domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included