SCAZT · domain
Cloud Security Architecture
Practise Cisco Designing and Implementing Secure Cloud Access for Users and Endpoints (SCAZT, 300-740, CCNP Security) (SCAZT) Cloud Security Architecture practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice Cloud Security Architecture questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Cloud Security Architecture
Watch out for
Common Cloud Security Architecture exam traps
Question index
All Cloud Security Architecture questions (47)
Click any question to see the full explanation, or start a practice session above.
Which TWO capabilities does Cisco Cloudlock bring to a SaaS environment?
Medium2You are configuring a SASE design to secure traffic from a branch office to the cloud. What is the recommended method for routing internet-bound traffic from the branch to the Cisco Umbrella SIG?
Medium3Which THREE features are provided by the Cisco Umbrella 'Intelligent Proxy'?
Hard4When implementing a Zero Trust architecture, what is the 'Principle of Least Privilege' (PoLP) specifically intended to achieve?
Easy5In a SASE deployment, why is the integration between Cisco ISE and Cisco Secure Access considered a critical design pattern?
Medium6Which THREE criteria are used by Cisco Secure Access to determine if a connection should be allowed?
Hard7Which feature of the Cisco Umbrella SIG is specifically designed to prevent 'Command and Control' (C2) callbacks from infected endpoints?
Medium8Which of the following is a key component of a successful 'Identity and Access Management' (IAM) strategy in the cloud?
Easy9In a SASE deployment using Cisco SD-WAN and Umbrella, how is traffic steered to the cloud security stack when a branch router loses its direct tunnel connection to the Umbrella SIG headend?
Hard10Which TWO identity sources can be integrated with Cisco Duo for user authentication?
Medium11Which TWO methods can be used to tunnel traffic from a branch office to the Cisco Umbrella SIG?
Hard12When deploying a secure remote access solution, how do you handle 'Split Tunneling' safely in a Zero Trust environment?
Hard13A network architect is deploying Cisco Umbrella SIG to enforce Zero Trust access. Which mechanism provides the initial posture assessment before allowing a user to access a SaaS application via the Secure Web Gateway?
Medium14A firm is adopting SASE and needs to secure mobile devices. Which component of the Cisco SASE suite is best suited to protect mobile endpoints?
Medium15You are designing a secure hybrid cloud environment and need to ensure that traffic between the public cloud and private data center is inspected. Which architecture pattern is most effective?
Hard16Which TWO components are essential for implementing a Zero Trust Network Access (ZTNA) model using Cisco Duo and Secure Access?
Medium17When designing a Secure Access Service Edge (SASE) architecture, which principle best describes the shift from traditional hub-and-spoke networking?
Easy18When evaluating cloud security reference architectures, what is the primary purpose of a 'Cloud Access Security Broker' (CASB)?
Easy19Which capability of the Cisco Umbrella SIG ensures that sensitive data, such as PII or credit card numbers, does not leave the organization via web traffic?
Medium20Which Cisco technology should be used to provide visibility and threat detection for traffic traversing between cloud workloads in a VPC?
Medium21When designing for high availability in a SASE architecture, which THREE strategies are recommended?
Hard22Which TWO of the following are primary components of the Cisco SASE security stack?
Medium23What is the primary benefit of using 'SAML' (Security Assertion Markup Language) for cloud application authentication?
Medium24A user is attempting to access a SaaS application, but the session is blocked by Cisco Cloudlock due to a detected policy violation. Which component is responsible for analyzing the API calls and triggering the remediation?
Medium25Which component of the Cisco SASE architecture provides the primary security enforcement point for remote users browsing the web from untrusted networks?
Easy26You are troubleshooting a connection issue where a remote user cannot access a private cloud application via the Cisco Secure Access ZTNA connector. Which step is most likely to resolve the issue?
Hard27Which TWO features of Cisco Umbrella assist in preventing data loss?
Medium28A user is using a managed laptop. How does 'Device Posture' in the Cisco SASE model verify that an antivirus solution is active?
Medium29Which THREE factors influence the performance of a SASE deployment?
Hard30Which Cisco product facilitates 'Cloud-to-Cloud' security by monitoring activities in SaaS platforms like Microsoft 365?
Easy31When designing a cloud security architecture, why is 'logging and observability' so critical?
Medium32An organization is deploying Cisco Umbrella SIG to enforce Zero Trust access. You must configure the selective decryption policy. Which setting ensures that specific sensitive traffic, such as financial and healthcare sites, is bypassed for inspection to comply with privacy regulations?
Medium33A global company needs to ensure that users in different regions have the lowest latency when accessing cloud applications. How should the SASE architecture be configured?
Medium34Which THREE factors are typically considered when evaluating 'Device Posture' in a Zero Trust environment?
Medium35Why is 'SSL/TLS Inspection' necessary in a SASE architecture?
Medium36Which THREE components are critical to consider when designing a 'cloud security reference architecture'?
Hard37Which TWO are common 'secure access design patterns' in a hybrid cloud?
Medium38You are designing a secure access path for a BYOD device. What is the most effective approach to ensure the device does not compromise the network?
Hard39When designing a Zero Trust architecture using Cisco Secure Access, how does the 'Device Posture' check specifically influence the access decision for a managed laptop?
Hard40You are setting up a secure hybrid cloud environment. How do you implement 'Micro-segmentation' between virtual machines in the same subnet?
Hard41What is the primary goal of the 'Cisco SASE' framework?
Easy42In the context of SASE, what is the primary role of the 'Global Anycast Network'?
Medium43Which THREE factors should be considered when designing an IaaS security architecture using Cisco Secure Workload (formerly Tetration)?
Hard44Which THREE types of information are analyzed by Cisco Secure Workload (Tetration) to enforce micro-segmentation?
Hard45A security architect is designing a SASE solution. What is the significance of 'Identity-Based Segmentation' in this design?
Medium46You are designing a secure remote access solution for a hybrid cloud environment. Which Cisco technology should you implement to replace a traditional VPN while enforcing Zero Trust principles?
Hard47When implementing a ZTNA solution, which factor is most crucial when defining an 'Application Access Policy'?
HardOther domains
All SCAZT exam domains
Frequently asked questions
- What does the Cloud Security Architecture domain cover on the SCAZT exam?
- Cloud concepts questions usually test the service model (IaaS/PaaS/SaaS) and deployment model (public/private/hybrid/community) appropriate for a given scenario.
- How many questions are in this domain?
- This page lists all 47 Cloud Security Architecture questions in the SCAZT question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Cloud Security Architecture questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.