Courseiva

350-701 · domain

Cloud Security

Practise Cisco SCOR / CCNP Security Core 350-701 Cloud Security practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

79 questions18 easy40 medium21 hard

Focused practice

Practice Cloud Security questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Cloud Security

Cloud concepts questions usually test the service model (IaaS/PaaS/SaaS) and deployment model (public/private/hybrid/community) appropriate for a given scenario.

IaaS, PaaS and SaaS responsibilities and examples.

Public, private, hybrid and community cloud deployment models.

On-premises vs cloud trade-offs: cost, control, scalability.

How cloud connectivity options (VPN, Direct Connect, ExpressRoute) work.

Watch out for

Common Cloud Security exam traps

  • IaaS gives you infrastructure control; SaaS gives you only the application.
  • Hybrid cloud combines on-premises and public cloud — not two public clouds.
  • Cloud does not automatically mean cheaper or more secure.
  • Management responsibility shifts with each service model (IaaSPaaSSaaS).

Question index

All Cloud Security questions (79)

Click any question to see the full explanation, or start a practice session above.

1

An organization is adopting a zero trust model for cloud access. Which three principles should be implemented? (Select three.)

Medium
2

A DevOps team is integrating security into their CI/CD pipeline. They want to automatically scan Terraform scripts for misconfigurations before deployment. Which tool is specifically designed for this purpose?

Medium
3

A cloud security architect is designing zero trust for a multi-cloud environment. Which principle is most critical?

Hard
4

A security engineer is designing cloud workload protection (CWPP) for a hybrid environment with VMs and containers. Which TWO capabilities should a CWPP solution provide? (Choose two.)

Hard
5

An organization is implementing a zero trust strategy for cloud access. They require that all access to cloud resources be authenticated and authorized based on user identity and device health, with session risk assessment. Which Azure AD feature should they primarily use?

Hard
6

A company is deploying workloads in AWS and wants to ensure that the security groups are not overly permissive. They need to continuously monitor for misconfigurations and compare against the CIS AWS Foundations Benchmark. Which tool should be used?

Medium
7

In the shared responsibility model for PaaS, which of the following is typically the customer's responsibility?

Easy
8

A security administrator is evaluating Cisco Umbrella for cloud-delivered security. Which TWO capabilities are provided by the Secure Internet Gateway (SIG) feature? (Choose two.)

Medium
9

A security team wants to gain visibility into shadow IT usage of cloud applications and enforce data loss prevention policies. Which cloud security control should they deploy?

Medium
10

A DevSecOps team is integrating security into their CI/CD pipeline. They want to scan infrastructure-as-code templates for misconfigurations and container images for vulnerabilities. Which two tools are appropriate? (Select two.)

Medium
11

A DevSecOps team is integrating security into their CI/CD pipeline. They want to scan Terraform configuration files for misconfigurations before deployment. Which tool is specifically designed for that purpose?

Hard
12

A company is moving workloads to Google Cloud and needs private connectivity between its on-premises data center and VPC without traversing the internet. Which service should be used?

Medium
13

A company uses AWS and Azure and wants to protect its cloud workloads (VMs and containers) from threats. Which TWO technologies are specifically designed for workload protection in the cloud?

Hard
14

A cloud engineer is deploying a web application on AWS and needs to control inbound and outbound traffic at both the instance and subnet levels. Which two AWS security controls should they configure? (Select two.)

Easy
15

A security team is implementing CSPM to ensure cloud compliance. Which three checks would a CSPM tool typically perform? (Choose three.)

Hard
16

In AWS, which resource acts as a stateful firewall at the instance level to control inbound and outbound traffic?

Medium
17

An organization uses Cisco Umbrella's Secure Internet Gateway (SIG). Which of the following sets of capabilities is typically included in a SIG solution?

Medium
18

A company uses Azure and wants to restrict network traffic between subnets. Which Azure resource should they use?

Medium
19

An organization uses multiple SaaS applications and wants to enforce data loss prevention (DLP) policies to prevent sensitive data from being shared externally. Which cloud security solution should be deployed?

Medium
20

A security team is implementing a DevSecOps pipeline for containerized applications. Which TWO of the following practices should be included to ensure container security?

Medium
21

A security team wants to enforce data loss prevention (DLP) policies across multiple sanctioned cloud applications used by employees. Which cloud security solution is best suited for this task?

Medium
22

In the shared responsibility model for cloud services, which layer is the customer responsible for managing in an IaaS environment?

Easy
23

An organization uses AWS WAF to protect its web application. They need to block requests from a specific geographic region. What should they configure?

Hard
24

An organization uses Cisco Umbrella to block malicious domains. What is the primary security benefit of DNS-layer security?

Medium
25

A security engineer needs to prevent secrets (e.g., API keys) from being stored in code repositories. Which DevSecOps practice should be implemented?

Hard
26

A security engineer is configuring Cisco Umbrella to block HTTPS traffic to malicious sites. However, they want to inspect SSL-encrypted traffic selectively to avoid breaking applications. Which Umbrella feature should they use?

Medium
27

A company uses Cisco Umbrella to protect remote users. They want to ensure that SSL-encrypted traffic to malicious websites is inspected, but without breaking compliance with privacy regulations. Which Umbrella feature should they enable?

Medium
28

A company uses a SaaS application for customer relationship management. In the cloud shared responsibility model, which security controls are the customer's primary responsibility?

Easy
29

A security team wants to gain visibility into shadow IT usage of SaaS applications and enforce DLP policies for data shared via cloud apps. Which cloud security solution should they deploy?

Medium
30

A security engineer is configuring Cisco Umbrella to enforce web security for remote users. The requirement is to block threats by intercepting DNS requests and only perform SSL decryption on specific high-risk categories. Which Umbrella feature should be used for selective SSL inspection?

Hard
31

A company is deploying Cisco Umbrella with the Intelligent Proxy feature. Under what condition does the Intelligent Proxy perform SSL decryption?

Hard
32

A security architect is designing a zero-trust model for cloud access. Which of the following is a core principle of zero trust in the cloud?

Hard
33

An organization wants to connect its on-premises data center to an AWS VPC privately, avoiding the public internet. Which AWS service provides a dedicated, private connection?

Medium
34

In the shared responsibility model, which is the customer's responsibility in a SaaS model?

Easy
35

A company is using Cisco Umbrella for cloud security. Which two features are part of the Secure Internet Gateway (SIG) functionality? (Choose two.)

Medium
36

In the shared responsibility model for PaaS, which component is the customer responsible for managing?

Easy
37

Which of the following is the primary function of a Cloud Security Posture Management (CSPM) tool?

Easy
38

An organization is adopting zero trust principles for cloud access. Which THREE components should be implemented to enforce identity as the new perimeter?

Medium
39

A security team is implementing secure access for remote users connecting from untrusted networks. They want to enforce DNS-layer security even when users are off the corporate network. Which Cisco Umbrella feature should be deployed on the endpoints?

Medium
40

Which two controls are considered part of a zero-trust architecture for cloud access? (Choose two.)

Medium
41

An organization uses Azure for its cloud workloads. To protect web applications from common exploits like SQL injection and cross-site scripting, they need to deploy a web application firewall (WAF) that integrates with Azure Application Gateway. Which Azure WAF SKU should they choose?

Hard
42

A security team is implementing DevSecOps practices. Which TWO actions should be taken to secure secrets (e.g., API keys, passwords) in a CI/CD pipeline? (Choose two.)

Medium
43

A security engineer is configuring Cisco Umbrella Intelligent Proxy to selectively decrypt and inspect HTTPS traffic. The goal is to balance security and user privacy by only inspecting traffic to high-risk domains. How does Intelligent Proxy decide which traffic to inspect?

Hard
44

A company is deploying a multi-tier application on AWS. The web servers must be accessible from the internet only on ports 80 and 443, while the database servers should be accessible only from the web servers on port 3306. Which combination of cloud network security controls should be used?

Hard
45

A security administrator wants to enforce a policy that blocks upload of sensitive data to unauthorized cloud applications. Which technology should be used to gain visibility and control over sanctioned and unsanctioned SaaS applications?

Medium
46

An organization wants to enforce MFA for all administrative access to their Azure environment and also require that access from non-compliant devices be blocked. Which Azure feature should they use?

Medium
47

Which Cisco Umbrella feature provides off-network protection by intercepting DNS requests on a user's device?

Easy
48

A company is using a SaaS application like Office 365. Which security responsibility falls on the customer according to the shared responsibility model?

Easy
49

A company uses Azure AD Conditional Access policies to enforce security for cloud applications. They need to require MFA for all external users accessing a sensitive SaaS app, but only when the access is from an untrusted network. Which condition should be configured in the policy?

Hard
50

An organization wants to implement zero trust principles for cloud access. Which of the following is a key component of a zero trust architecture in the cloud?

Easy
51

A security team is implementing AWS WAF to protect a web application. They want to block requests that contain SQL injection patterns in the query string. Which AWS WAF component should be used?

Medium
52

In a DevSecOps pipeline, which tool would be used to scan Infrastructure as Code (IaC) templates for security misconfigurations?

Easy
53

A security team wants to inspect SSL-encrypted traffic from users accessing SaaS applications through Cisco Umbrella. Which feature should they enable?

Medium
54

A security team wants to gain visibility into Shadow IT usage of SaaS applications and enforce data loss prevention policies. Which cloud security solution should they deploy?

Medium
55

In the shared responsibility model for cloud computing, which responsibility is managed by the customer in all service models (IaaS, PaaS, SaaS)?

Easy
56

A company is adopting a zero-trust security model for its cloud environment. Which THREE practices align with zero-trust principles? (Choose three.)

Medium
57

An organization is adopting zero trust principles for cloud access. Which THREE measures are essential for implementing identity-centric security? (Choose three.)

Hard
58

An organization uses Cisco Umbrella to protect remote users. The security team notices that some malicious domains are not blocked because users are bypassing the DNS layer by using direct IP connections or non-DNS protocols. Which Cisco Umbrella feature should be enabled to inspect all traffic, including non-web traffic, and enforce policies regardless of DNS resolution?

Hard
59

An organization uses Cisco Umbrella to block malicious domains. The security team notices that some malware traffic bypasses DNS-layer blocking because the malware uses hardcoded IP addresses. Which Umbrella feature should be enabled to additionally inspect traffic at the IP layer?

Medium
60

An organization is adopting a zero-trust model for cloud access. Which component enforces conditional access policies based on user, device, location, and risk level in Azure AD?

Medium
61

A company uses Cisco Umbrella to provide DNS-layer security. An employee tries to visit a website that is hosting malware, but the domain is not yet categorized. How does Umbrella handle this request?

Medium
62

A company is moving its on-premises applications to AWS EC2 instances. According to the shared responsibility model, which of the following is the customer's responsibility?

Easy
63

An organization uses Cisco Umbrella to block malicious domains. Which layer does Umbrella primarily operate at to prevent connections before they are established?

Medium
64

Which cloud security control is specifically designed to protect workloads such as VMs and containers from threats?

Easy
65

A company uses multiple SaaS applications and wants to enforce data loss prevention (DLP) policies to prevent sensitive data from being shared externally. Which technology provides the ability to scan data in transit and at rest within these SaaS applications?

Medium
66

In the shared responsibility model for PaaS, which of the following is the customer responsible for?

Easy
67

A company is using Azure and wants to enforce security compliance across their cloud resources. Which TWO services are part of CSPM (Cloud Security Posture Management) in Azure? (Choose two.)

Medium
68

Which cloud workload protection platform (CWPP) capability is essential for protecting containerized applications?

Medium
69

To enforce zero trust principles in a cloud environment, an administrator requires all access to cloud resources to be authenticated and authorized based on user identity and device health. Which Cisco Duo feature enables policies that consider conditions such as location, device compliance, and risk level?

Medium
70

In a DevSecOps pipeline, a team wants to prevent secrets (e.g., API keys) from being stored in source code. Which approach is most effective?

Hard
71

In a DevSecOps pipeline, a security engineer wants to automatically scan Infrastructure as Code (IaC) templates for security misconfigurations before deployment. Which tool is commonly used for static analysis of Terraform templates?

Easy
72

An organization is deploying containerized applications in a Kubernetes cluster on AWS EKS. They need to ensure that container images are scanned for vulnerabilities before deployment. Which approach aligns with DevSecOps best practices?

Hard
73

A DevSecOps team is implementing secrets management for a cloud-native application. They want to avoid storing secrets in environment variables or code. Which solution should they use?

Hard
74

A company wants to ensure that no cloud workload has a public IP address attached to a network security policy that allows inbound SSH from the entire internet. Which Cisco security product can continuously monitor and alert on such misconfigurations?

Hard
75

In the shared responsibility model for cloud security, which of the following is the customer responsible for in an IaaS deployment?

Easy
76

A DevOps team is building a CI/CD pipeline for a cloud-native application. They want to automatically check Terraform scripts for insecure configurations before deployment. Which tool should be integrated into the pipeline?

Medium
77

In the shared responsibility model for cloud security, which responsibility is the customer's in an IaaS deployment?

Easy
78

A company is deploying a multi-tier application in a Cisco cloud security environment. The web servers must be accessible from the internet, but the database servers should only be reachable from the web servers. Which Cisco security controls should be used to enforce this?

Medium
79

An organization wants to protect their web application hosted on AWS from common exploits like SQL injection. Which Cisco service should they use?

Medium

Frequently asked questions

What does the Cloud Security domain cover on the 350-701 exam?
Cloud concepts questions usually test the service model (IaaS/PaaS/SaaS) and deployment model (public/private/hybrid/community) appropriate for a given scenario.
How many questions are in this domain?
This page lists all 79 Cloud Security questions in the 350-701 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Cloud Security questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
cisco-ccnp-security CISCO-CCNP-SECURITY scor cloud security Practice Questions