350-701 · domain
Cloud Security
Practise Cisco SCOR / CCNP Security Core 350-701 Cloud Security practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice Cloud Security questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Cloud Security
Watch out for
Common Cloud Security exam traps
Question index
All Cloud Security questions (79)
Click any question to see the full explanation, or start a practice session above.
An organization is adopting a zero trust model for cloud access. Which three principles should be implemented? (Select three.)
Medium2A DevOps team is integrating security into their CI/CD pipeline. They want to automatically scan Terraform scripts for misconfigurations before deployment. Which tool is specifically designed for this purpose?
Medium3A cloud security architect is designing zero trust for a multi-cloud environment. Which principle is most critical?
Hard4A security engineer is designing cloud workload protection (CWPP) for a hybrid environment with VMs and containers. Which TWO capabilities should a CWPP solution provide? (Choose two.)
Hard5An organization is implementing a zero trust strategy for cloud access. They require that all access to cloud resources be authenticated and authorized based on user identity and device health, with session risk assessment. Which Azure AD feature should they primarily use?
Hard6A company is deploying workloads in AWS and wants to ensure that the security groups are not overly permissive. They need to continuously monitor for misconfigurations and compare against the CIS AWS Foundations Benchmark. Which tool should be used?
Medium7In the shared responsibility model for PaaS, which of the following is typically the customer's responsibility?
Easy8A security administrator is evaluating Cisco Umbrella for cloud-delivered security. Which TWO capabilities are provided by the Secure Internet Gateway (SIG) feature? (Choose two.)
Medium9A security team wants to gain visibility into shadow IT usage of cloud applications and enforce data loss prevention policies. Which cloud security control should they deploy?
Medium10A DevSecOps team is integrating security into their CI/CD pipeline. They want to scan infrastructure-as-code templates for misconfigurations and container images for vulnerabilities. Which two tools are appropriate? (Select two.)
Medium11A DevSecOps team is integrating security into their CI/CD pipeline. They want to scan Terraform configuration files for misconfigurations before deployment. Which tool is specifically designed for that purpose?
Hard12A company is moving workloads to Google Cloud and needs private connectivity between its on-premises data center and VPC without traversing the internet. Which service should be used?
Medium13A company uses AWS and Azure and wants to protect its cloud workloads (VMs and containers) from threats. Which TWO technologies are specifically designed for workload protection in the cloud?
Hard14A cloud engineer is deploying a web application on AWS and needs to control inbound and outbound traffic at both the instance and subnet levels. Which two AWS security controls should they configure? (Select two.)
Easy15A security team is implementing CSPM to ensure cloud compliance. Which three checks would a CSPM tool typically perform? (Choose three.)
Hard16In AWS, which resource acts as a stateful firewall at the instance level to control inbound and outbound traffic?
Medium17An organization uses Cisco Umbrella's Secure Internet Gateway (SIG). Which of the following sets of capabilities is typically included in a SIG solution?
Medium18A company uses Azure and wants to restrict network traffic between subnets. Which Azure resource should they use?
Medium19An organization uses multiple SaaS applications and wants to enforce data loss prevention (DLP) policies to prevent sensitive data from being shared externally. Which cloud security solution should be deployed?
Medium20A security team is implementing a DevSecOps pipeline for containerized applications. Which TWO of the following practices should be included to ensure container security?
Medium21A security team wants to enforce data loss prevention (DLP) policies across multiple sanctioned cloud applications used by employees. Which cloud security solution is best suited for this task?
Medium22In the shared responsibility model for cloud services, which layer is the customer responsible for managing in an IaaS environment?
Easy23An organization uses AWS WAF to protect its web application. They need to block requests from a specific geographic region. What should they configure?
Hard24An organization uses Cisco Umbrella to block malicious domains. What is the primary security benefit of DNS-layer security?
Medium25A security engineer needs to prevent secrets (e.g., API keys) from being stored in code repositories. Which DevSecOps practice should be implemented?
Hard26A security engineer is configuring Cisco Umbrella to block HTTPS traffic to malicious sites. However, they want to inspect SSL-encrypted traffic selectively to avoid breaking applications. Which Umbrella feature should they use?
Medium27A company uses Cisco Umbrella to protect remote users. They want to ensure that SSL-encrypted traffic to malicious websites is inspected, but without breaking compliance with privacy regulations. Which Umbrella feature should they enable?
Medium28A company uses a SaaS application for customer relationship management. In the cloud shared responsibility model, which security controls are the customer's primary responsibility?
Easy29A security team wants to gain visibility into shadow IT usage of SaaS applications and enforce DLP policies for data shared via cloud apps. Which cloud security solution should they deploy?
Medium30A security engineer is configuring Cisco Umbrella to enforce web security for remote users. The requirement is to block threats by intercepting DNS requests and only perform SSL decryption on specific high-risk categories. Which Umbrella feature should be used for selective SSL inspection?
Hard31A company is deploying Cisco Umbrella with the Intelligent Proxy feature. Under what condition does the Intelligent Proxy perform SSL decryption?
Hard32A security architect is designing a zero-trust model for cloud access. Which of the following is a core principle of zero trust in the cloud?
Hard33An organization wants to connect its on-premises data center to an AWS VPC privately, avoiding the public internet. Which AWS service provides a dedicated, private connection?
Medium34In the shared responsibility model, which is the customer's responsibility in a SaaS model?
Easy35A company is using Cisco Umbrella for cloud security. Which two features are part of the Secure Internet Gateway (SIG) functionality? (Choose two.)
Medium36In the shared responsibility model for PaaS, which component is the customer responsible for managing?
Easy37Which of the following is the primary function of a Cloud Security Posture Management (CSPM) tool?
Easy38An organization is adopting zero trust principles for cloud access. Which THREE components should be implemented to enforce identity as the new perimeter?
Medium39A security team is implementing secure access for remote users connecting from untrusted networks. They want to enforce DNS-layer security even when users are off the corporate network. Which Cisco Umbrella feature should be deployed on the endpoints?
Medium40Which two controls are considered part of a zero-trust architecture for cloud access? (Choose two.)
Medium41An organization uses Azure for its cloud workloads. To protect web applications from common exploits like SQL injection and cross-site scripting, they need to deploy a web application firewall (WAF) that integrates with Azure Application Gateway. Which Azure WAF SKU should they choose?
Hard42A security team is implementing DevSecOps practices. Which TWO actions should be taken to secure secrets (e.g., API keys, passwords) in a CI/CD pipeline? (Choose two.)
Medium43A security engineer is configuring Cisco Umbrella Intelligent Proxy to selectively decrypt and inspect HTTPS traffic. The goal is to balance security and user privacy by only inspecting traffic to high-risk domains. How does Intelligent Proxy decide which traffic to inspect?
Hard44A company is deploying a multi-tier application on AWS. The web servers must be accessible from the internet only on ports 80 and 443, while the database servers should be accessible only from the web servers on port 3306. Which combination of cloud network security controls should be used?
Hard45A security administrator wants to enforce a policy that blocks upload of sensitive data to unauthorized cloud applications. Which technology should be used to gain visibility and control over sanctioned and unsanctioned SaaS applications?
Medium46An organization wants to enforce MFA for all administrative access to their Azure environment and also require that access from non-compliant devices be blocked. Which Azure feature should they use?
Medium47Which Cisco Umbrella feature provides off-network protection by intercepting DNS requests on a user's device?
Easy48A company is using a SaaS application like Office 365. Which security responsibility falls on the customer according to the shared responsibility model?
Easy49A company uses Azure AD Conditional Access policies to enforce security for cloud applications. They need to require MFA for all external users accessing a sensitive SaaS app, but only when the access is from an untrusted network. Which condition should be configured in the policy?
Hard50An organization wants to implement zero trust principles for cloud access. Which of the following is a key component of a zero trust architecture in the cloud?
Easy51A security team is implementing AWS WAF to protect a web application. They want to block requests that contain SQL injection patterns in the query string. Which AWS WAF component should be used?
Medium52In a DevSecOps pipeline, which tool would be used to scan Infrastructure as Code (IaC) templates for security misconfigurations?
Easy53A security team wants to inspect SSL-encrypted traffic from users accessing SaaS applications through Cisco Umbrella. Which feature should they enable?
Medium54A security team wants to gain visibility into Shadow IT usage of SaaS applications and enforce data loss prevention policies. Which cloud security solution should they deploy?
Medium55In the shared responsibility model for cloud computing, which responsibility is managed by the customer in all service models (IaaS, PaaS, SaaS)?
Easy56A company is adopting a zero-trust security model for its cloud environment. Which THREE practices align with zero-trust principles? (Choose three.)
Medium57An organization is adopting zero trust principles for cloud access. Which THREE measures are essential for implementing identity-centric security? (Choose three.)
Hard58An organization uses Cisco Umbrella to protect remote users. The security team notices that some malicious domains are not blocked because users are bypassing the DNS layer by using direct IP connections or non-DNS protocols. Which Cisco Umbrella feature should be enabled to inspect all traffic, including non-web traffic, and enforce policies regardless of DNS resolution?
Hard59An organization uses Cisco Umbrella to block malicious domains. The security team notices that some malware traffic bypasses DNS-layer blocking because the malware uses hardcoded IP addresses. Which Umbrella feature should be enabled to additionally inspect traffic at the IP layer?
Medium60An organization is adopting a zero-trust model for cloud access. Which component enforces conditional access policies based on user, device, location, and risk level in Azure AD?
Medium61A company uses Cisco Umbrella to provide DNS-layer security. An employee tries to visit a website that is hosting malware, but the domain is not yet categorized. How does Umbrella handle this request?
Medium62A company is moving its on-premises applications to AWS EC2 instances. According to the shared responsibility model, which of the following is the customer's responsibility?
Easy63An organization uses Cisco Umbrella to block malicious domains. Which layer does Umbrella primarily operate at to prevent connections before they are established?
Medium64Which cloud security control is specifically designed to protect workloads such as VMs and containers from threats?
Easy65A company uses multiple SaaS applications and wants to enforce data loss prevention (DLP) policies to prevent sensitive data from being shared externally. Which technology provides the ability to scan data in transit and at rest within these SaaS applications?
Medium66In the shared responsibility model for PaaS, which of the following is the customer responsible for?
Easy67A company is using Azure and wants to enforce security compliance across their cloud resources. Which TWO services are part of CSPM (Cloud Security Posture Management) in Azure? (Choose two.)
Medium68Which cloud workload protection platform (CWPP) capability is essential for protecting containerized applications?
Medium69To enforce zero trust principles in a cloud environment, an administrator requires all access to cloud resources to be authenticated and authorized based on user identity and device health. Which Cisco Duo feature enables policies that consider conditions such as location, device compliance, and risk level?
Medium70In a DevSecOps pipeline, a team wants to prevent secrets (e.g., API keys) from being stored in source code. Which approach is most effective?
Hard71In a DevSecOps pipeline, a security engineer wants to automatically scan Infrastructure as Code (IaC) templates for security misconfigurations before deployment. Which tool is commonly used for static analysis of Terraform templates?
Easy72An organization is deploying containerized applications in a Kubernetes cluster on AWS EKS. They need to ensure that container images are scanned for vulnerabilities before deployment. Which approach aligns with DevSecOps best practices?
Hard73A DevSecOps team is implementing secrets management for a cloud-native application. They want to avoid storing secrets in environment variables or code. Which solution should they use?
Hard74A company wants to ensure that no cloud workload has a public IP address attached to a network security policy that allows inbound SSH from the entire internet. Which Cisco security product can continuously monitor and alert on such misconfigurations?
Hard75In the shared responsibility model for cloud security, which of the following is the customer responsible for in an IaaS deployment?
Easy76A DevOps team is building a CI/CD pipeline for a cloud-native application. They want to automatically check Terraform scripts for insecure configurations before deployment. Which tool should be integrated into the pipeline?
Medium77In the shared responsibility model for cloud security, which responsibility is the customer's in an IaaS deployment?
Easy78A company is deploying a multi-tier application in a Cisco cloud security environment. The web servers must be accessible from the internet, but the database servers should only be reachable from the web servers. Which Cisco security controls should be used to enforce this?
Medium79An organization wants to protect their web application hosted on AWS from common exploits like SQL injection. Which Cisco service should they use?
MediumOther domains
All 350-701 exam domains
Frequently asked questions
- What does the Cloud Security domain cover on the 350-701 exam?
- Cloud concepts questions usually test the service model (IaaS/PaaS/SaaS) and deployment model (public/private/hybrid/community) appropriate for a given scenario.
- How many questions are in this domain?
- This page lists all 79 Cloud Security questions in the 350-701 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Cloud Security questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.