Courseiva

SCAZT · domain

Cloud Security Architecture

Practise Cisco Designing and Implementing Secure Cloud Access for Users and Endpoints (SCAZT, 300-740, CCNP Security) (SCAZT) Cloud Security Architecture practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

47 questions7 easy23 medium17 hard

Focused practice

Practice Cloud Security Architecture questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Cloud Security Architecture

Cloud concepts questions usually test the service model (IaaS/PaaS/SaaS) and deployment model (public/private/hybrid/community) appropriate for a given scenario.

IaaS, PaaS and SaaS responsibilities and examples.

Public, private, hybrid and community cloud deployment models.

On-premises vs cloud trade-offs: cost, control, scalability.

How cloud connectivity options (VPN, Direct Connect, ExpressRoute) work.

Watch out for

Common Cloud Security Architecture exam traps

  • IaaS gives you infrastructure control; SaaS gives you only the application.
  • Hybrid cloud combines on-premises and public cloud — not two public clouds.
  • Cloud does not automatically mean cheaper or more secure.
  • Management responsibility shifts with each service model (IaaSPaaSSaaS).

Question index

All Cloud Security Architecture questions (47)

Click any question to see the full explanation, or start a practice session above.

1

Which TWO capabilities does Cisco Cloudlock bring to a SaaS environment?

Medium
2

You are configuring a SASE design to secure traffic from a branch office to the cloud. What is the recommended method for routing internet-bound traffic from the branch to the Cisco Umbrella SIG?

Medium
3

Which THREE features are provided by the Cisco Umbrella 'Intelligent Proxy'?

Hard
4

When implementing a Zero Trust architecture, what is the 'Principle of Least Privilege' (PoLP) specifically intended to achieve?

Easy
5

In a SASE deployment, why is the integration between Cisco ISE and Cisco Secure Access considered a critical design pattern?

Medium
6

Which THREE criteria are used by Cisco Secure Access to determine if a connection should be allowed?

Hard
7

Which feature of the Cisco Umbrella SIG is specifically designed to prevent 'Command and Control' (C2) callbacks from infected endpoints?

Medium
8

Which of the following is a key component of a successful 'Identity and Access Management' (IAM) strategy in the cloud?

Easy
9

In a SASE deployment using Cisco SD-WAN and Umbrella, how is traffic steered to the cloud security stack when a branch router loses its direct tunnel connection to the Umbrella SIG headend?

Hard
10

Which TWO identity sources can be integrated with Cisco Duo for user authentication?

Medium
11

Which TWO methods can be used to tunnel traffic from a branch office to the Cisco Umbrella SIG?

Hard
12

When deploying a secure remote access solution, how do you handle 'Split Tunneling' safely in a Zero Trust environment?

Hard
13

A network architect is deploying Cisco Umbrella SIG to enforce Zero Trust access. Which mechanism provides the initial posture assessment before allowing a user to access a SaaS application via the Secure Web Gateway?

Medium
14

A firm is adopting SASE and needs to secure mobile devices. Which component of the Cisco SASE suite is best suited to protect mobile endpoints?

Medium
15

You are designing a secure hybrid cloud environment and need to ensure that traffic between the public cloud and private data center is inspected. Which architecture pattern is most effective?

Hard
16

Which TWO components are essential for implementing a Zero Trust Network Access (ZTNA) model using Cisco Duo and Secure Access?

Medium
17

When designing a Secure Access Service Edge (SASE) architecture, which principle best describes the shift from traditional hub-and-spoke networking?

Easy
18

When evaluating cloud security reference architectures, what is the primary purpose of a 'Cloud Access Security Broker' (CASB)?

Easy
19

Which capability of the Cisco Umbrella SIG ensures that sensitive data, such as PII or credit card numbers, does not leave the organization via web traffic?

Medium
20

Which Cisco technology should be used to provide visibility and threat detection for traffic traversing between cloud workloads in a VPC?

Medium
21

When designing for high availability in a SASE architecture, which THREE strategies are recommended?

Hard
22

Which TWO of the following are primary components of the Cisco SASE security stack?

Medium
23

What is the primary benefit of using 'SAML' (Security Assertion Markup Language) for cloud application authentication?

Medium
24

A user is attempting to access a SaaS application, but the session is blocked by Cisco Cloudlock due to a detected policy violation. Which component is responsible for analyzing the API calls and triggering the remediation?

Medium
25

Which component of the Cisco SASE architecture provides the primary security enforcement point for remote users browsing the web from untrusted networks?

Easy
26

You are troubleshooting a connection issue where a remote user cannot access a private cloud application via the Cisco Secure Access ZTNA connector. Which step is most likely to resolve the issue?

Hard
27

Which TWO features of Cisco Umbrella assist in preventing data loss?

Medium
28

A user is using a managed laptop. How does 'Device Posture' in the Cisco SASE model verify that an antivirus solution is active?

Medium
29

Which THREE factors influence the performance of a SASE deployment?

Hard
30

Which Cisco product facilitates 'Cloud-to-Cloud' security by monitoring activities in SaaS platforms like Microsoft 365?

Easy
31

When designing a cloud security architecture, why is 'logging and observability' so critical?

Medium
32

An organization is deploying Cisco Umbrella SIG to enforce Zero Trust access. You must configure the selective decryption policy. Which setting ensures that specific sensitive traffic, such as financial and healthcare sites, is bypassed for inspection to comply with privacy regulations?

Medium
33

A global company needs to ensure that users in different regions have the lowest latency when accessing cloud applications. How should the SASE architecture be configured?

Medium
34

Which THREE factors are typically considered when evaluating 'Device Posture' in a Zero Trust environment?

Medium
35

Why is 'SSL/TLS Inspection' necessary in a SASE architecture?

Medium
36

Which THREE components are critical to consider when designing a 'cloud security reference architecture'?

Hard
37

Which TWO are common 'secure access design patterns' in a hybrid cloud?

Medium
38

You are designing a secure access path for a BYOD device. What is the most effective approach to ensure the device does not compromise the network?

Hard
39

When designing a Zero Trust architecture using Cisco Secure Access, how does the 'Device Posture' check specifically influence the access decision for a managed laptop?

Hard
40

You are setting up a secure hybrid cloud environment. How do you implement 'Micro-segmentation' between virtual machines in the same subnet?

Hard
41

What is the primary goal of the 'Cisco SASE' framework?

Easy
42

In the context of SASE, what is the primary role of the 'Global Anycast Network'?

Medium
43

Which THREE factors should be considered when designing an IaaS security architecture using Cisco Secure Workload (formerly Tetration)?

Hard
44

Which THREE types of information are analyzed by Cisco Secure Workload (Tetration) to enforce micro-segmentation?

Hard
45

A security architect is designing a SASE solution. What is the significance of 'Identity-Based Segmentation' in this design?

Medium
46

You are designing a secure remote access solution for a hybrid cloud environment. Which Cisco technology should you implement to replace a traditional VPN while enforcing Zero Trust principles?

Hard
47

When implementing a ZTNA solution, which factor is most crucial when defining an 'Application Access Policy'?

Hard

Frequently asked questions

What does the Cloud Security Architecture domain cover on the SCAZT exam?
Cloud concepts questions usually test the service model (IaaS/PaaS/SaaS) and deployment model (public/private/hybrid/community) appropriate for a given scenario.
How many questions are in this domain?
This page lists all 47 Cloud Security Architecture questions in the SCAZT question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Cloud Security Architecture questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
cisco-scazt CISCO-SCAZT cloud security architecture Practice Questions