Courseiva

CCNA Cloud Security Architecture Questions

47 questions · Cloud Security Architecture · All types, answers revealed

1
Multi-Selectmedium

Which TWO capabilities does Cisco Cloudlock bring to a SaaS environment?

Select 2 answers
A.Power management for laptops
B.Data Loss Prevention (DLP)
C.Automatic server patching
D.Physical building access control
E.Account compromise detection
AnswersB, E

Cloudlock monitors for PII and other sensitive data in SaaS files.

Why this answer

Cloudlock provides DLP for sensitive data and threat detection for compromised accounts.

2
MCQmedium

You are configuring a SASE design to secure traffic from a branch office to the cloud. What is the recommended method for routing internet-bound traffic from the branch to the Cisco Umbrella SIG?

A.Configure DNS forwarding only.
B.Use an AnyConnect agent on every endpoint in the branch.
C.Deploy a local proxy server that intercepts all traffic.
D.Establish an IPsec tunnel from the branch edge device to the nearest Umbrella data center.
AnswerD

IPsec tunneling is the standard design pattern for branch-to-cloud security.

Why this answer

IPsec tunnels from the branch edge device (such as a Cisco ISR or Meraki MX) to the Cisco Umbrella SIG provide a secure, encrypted transit for all traffic.

3
Multi-Selecthard

Which THREE features are provided by the Cisco Umbrella 'Intelligent Proxy'?

Select 3 answers
A.Local DHCP server management
B.Hardware firewall replacement
C.File inspection for malware
D.URL filtering based on reputation
E.SSL/TLS inspection
AnswersC, D, E

The proxy scans files to block malicious payloads.

Why this answer

The Intelligent Proxy performs file analysis, URL filtering, and SSL inspection to protect users.

4
MCQeasy

When implementing a Zero Trust architecture, what is the 'Principle of Least Privilege' (PoLP) specifically intended to achieve?

A.Allowing open access to all company resources from the office.
B.Granting only the necessary permissions required for a user to perform their task.
C.Giving administrative access to all power users.
D.Automating the password rotation process.
AnswerB

This is the definition of PoLP in a Zero Trust context.

Why this answer

PoLP ensures that users and devices are granted the minimum level of access required to perform their jobs, minimizing the blast radius of a potential breach.

5
MCQmedium

In a SASE deployment, why is the integration between Cisco ISE and Cisco Secure Access considered a critical design pattern?

A.It enables direct firewall inspection of internal traffic.
B.It allows ISE to act as a cloud proxy server.
C.It enables context-aware policy enforcement based on user identity and device state across the hybrid environment.
D.It automates the deployment of AnyConnect agents.
AnswerC

This integration bridges the gap between campus network access and cloud service access policies.

Why this answer

Integrating ISE with Secure Access allows consistent policy application across both on-premises network resources and cloud-based applications.

6
Multi-Selecthard

Which THREE criteria are used by Cisco Secure Access to determine if a connection should be allowed?

Select 3 answers
A.User identity
B.The time of day the office was built
C.Device posture
D.Application-specific access policy
E.The user's favorite programming language
AnswersA, C, D

Confirming the user's identity is the first check.

Why this answer

Access decisions are made based on user identity, device posture, and the specific application policies.

7
MCQmedium

Which feature of the Cisco Umbrella SIG is specifically designed to prevent 'Command and Control' (C2) callbacks from infected endpoints?

A.Firewall-as-a-Service
B.SSL Decryption
C.DNS-layer security
D.Data Loss Prevention
AnswerC

Blocking the resolution of C2 domains prevents the malware from 'calling home'.

Why this answer

The Umbrella DNS layer security identifies and blocks requests to malicious domains associated with C2 infrastructure.

8
MCQeasy

Which of the following is a key component of a successful 'Identity and Access Management' (IAM) strategy in the cloud?

A.Centralized identity provider integration with MFA.
B.Creating a separate user account for each cloud application.
C.Allowing password sharing for shared service accounts.
D.Disabling MFA for administrative accounts for speed.
AnswerA

Centralization and MFA are pillars of secure cloud identity management.

Why this answer

A centralized IAM strategy, such as using an IdP (e.g., Azure AD or Okta) integrated with Cisco Duo, ensures consistent authentication.

9
MCQhard

In a SASE deployment using Cisco SD-WAN and Umbrella, how is traffic steered to the cloud security stack when a branch router loses its direct tunnel connection to the Umbrella SIG headend?

A.Local traffic is routed via MPLS only
B.Traffic is sent to the Umbrella VA
C.Traffic reverts to transparent proxy mode
D.Traffic is dropped by default
E.Automated tunnel failover to secondary Umbrella SIG DC
AnswerE

SD-WAN tunnels are multi-homed to multiple Umbrella data centers for redundancy.

Why this answer

Cisco SD-WAN uses Cloud OnRamp for SaaS/IaaS which automatically fails over to the next optimal gateway or local breakout based on configured SLA policies.

10
Multi-Selectmedium

Which TWO identity sources can be integrated with Cisco Duo for user authentication?

Select 2 answers
A.Excel spreadsheet export
B.OpenLDAP
C.Microsoft Active Directory
D.Local printer configuration file
E.Router configuration file
AnswersB, C

LDAP is natively supported by Duo.

Why this answer

Duo integrates with standard directories like Active Directory and LDAP.

11
Multi-Selecthard

Which TWO methods can be used to tunnel traffic from a branch office to the Cisco Umbrella SIG?

Select 2 answers
A.DNS-over-HTTPS
B.Bluetooth connectivity
C.HTTP Proxy (explicit)
D.GRE tunnel
E.IPsec tunnel
AnswersD, E

GRE is also a supported method for connecting branch traffic.

Why this answer

IPsec tunnels and GRE tunnels are the standard methods for connecting site-level traffic to the Umbrella cloud.

12
MCQhard

When deploying a secure remote access solution, how do you handle 'Split Tunneling' safely in a Zero Trust environment?

A.Disable split tunneling to ensure all traffic is inspected.
B.Use a ZTNA agent to tunnel only application-specific traffic while keeping web traffic direct.
C.Force all traffic through the corporate VPN, regardless of destination.
D.Allow all traffic to the internet without any inspection.
AnswerB

This allows for secure application access without hair-pinning all user traffic.

Why this answer

By using a ZTNA agent, you can define specific application tunnels, effectively creating a 'split' where only authorized traffic goes through the secure path while general web traffic goes direct.

13
MCQmedium

A network architect is deploying Cisco Umbrella SIG to enforce Zero Trust access. Which mechanism provides the initial posture assessment before allowing a user to access a SaaS application via the Secure Web Gateway?

A.Umbrella Virtual Appliance
B.Cloud-delivered Firewall
C.Umbrella DNS Policies
D.AnyConnect/Secure Client Posture Module
E.Umbrella SIG API
AnswerD

The Secure Client Posture module evaluates device criteria to ensure compliance before authorizing access.

Why this answer

The Cisco Umbrella Roaming Client or AnyConnect module performs device posture checks before establishing the tunnel.

14
MCQmedium

A firm is adopting SASE and needs to secure mobile devices. Which component of the Cisco SASE suite is best suited to protect mobile endpoints?

A.Cisco Secure Client (formerly AnyConnect) with Umbrella roaming module.
B.Cisco Meraki Systems Manager.
C.Cisco Cloudlock.
D.Cisco Stealthwatch.
AnswerA

This client ensures that traffic from the device is always routed through the Umbrella SIG.

Why this answer

The Cisco Umbrella roaming client (integrated with the AnyConnect/Cisco Secure Client) provides consistent protection for mobile devices off-network.

15
MCQhard

You are designing a secure hybrid cloud environment and need to ensure that traffic between the public cloud and private data center is inspected. Which architecture pattern is most effective?

A.Use a public load balancer without any security policies.
B.Rely on the cloud provider's default security groups only.
C.Allow all traffic to bypass the firewall for maximum speed.
D.Centralized inspection via a Transit Gateway with an integrated cloud firewall.
AnswerD

Transit Gateways provide a centralized point to force traffic through a virtual firewall appliance for inspection.

Why this answer

Implementing a cloud-native firewall in the VPC/VNet, paired with a transit gateway, allows for consistent inspection of all cross-environment traffic.

16
Multi-Selectmedium

Which TWO components are essential for implementing a Zero Trust Network Access (ZTNA) model using Cisco Duo and Secure Access?

Select 2 answers
A.Duo Authentication Proxy
B.Cisco Secure Firewall Management Center
C.Cisco Secure Access Connector
D.Cisco ISE
E.Umbrella Virtual Appliance
AnswersA, C

Essential for integrating legacy apps into the ZTNA flow.

Why this answer

ZTNA requires both identity verification (Duo) and policy-based access control (Secure Access).

17
MCQeasy

When designing a Secure Access Service Edge (SASE) architecture, which principle best describes the shift from traditional hub-and-spoke networking?

A.On-premise appliance chaining
B.Strict MPLS segmentation
C.Direct-to-cloud connectivity
D.Identity-agnostic security
E.Centralized backhauling
AnswerC

SASE enables users to connect directly to the cloud edge, minimizing latency.

Why this answer

SASE emphasizes connecting users directly to cloud resources rather than backhauling traffic to a central DC.

18
MCQeasy

When evaluating cloud security reference architectures, what is the primary purpose of a 'Cloud Access Security Broker' (CASB)?

A.To act as a secondary DNS server for the enterprise.
B.To manage physical access to cloud data centers.
C.To enforce security policies and provide visibility into SaaS and cloud applications.
D.To perform load balancing for cloud traffic.
AnswerC

This is the core function of a CASB.

Why this answer

A CASB sits between cloud service consumers and providers to enforce security policies, ensuring visibility, compliance, and threat protection.

19
MCQmedium

Which capability of the Cisco Umbrella SIG ensures that sensitive data, such as PII or credit card numbers, does not leave the organization via web traffic?

A.Firewall-as-a-Service (FWaaS)
B.Cloud-based Data Loss Prevention (DLP)
C.DNS-layer security
D.Intelligent Proxy
AnswerB

DLP inspects payloads to prevent unauthorized exfiltration.

Why this answer

Cisco Umbrella's Data Loss Prevention (DLP) capability inspects outgoing traffic for sensitive information based on pre-defined or custom data patterns.

20
MCQmedium

Which Cisco technology should be used to provide visibility and threat detection for traffic traversing between cloud workloads in a VPC?

A.Cisco Umbrella
B.Cisco AnyConnect
C.Cisco Secure Workload (Tetration)
D.Cisco Duo
AnswerC

Secure Workload provides granular visibility into inter-workload traffic.

Why this answer

Cisco Tetration (Secure Workload) provides micro-segmentation and deep observability of traffic between workloads to detect anomalies and threats.

21
Multi-Selecthard

When designing for high availability in a SASE architecture, which THREE strategies are recommended?

Select 3 answers
A.Dual ISP connections at the branch
B.Anycast network usage
C.Redundant IPsec tunnels to different Umbrella data centers
D.Assigning static IPs to all cloud users
E.Disabling all security features to improve uptime
AnswersA, B, C

Redundant internet links prevent downtime if one ISP fails.

Why this answer

Using multiple ISP connections, anycast routing, and redundant cloud tunnels ensures high availability.

22
Multi-Selectmedium

Which TWO of the following are primary components of the Cisco SASE security stack?

Select 2 answers
A.Cisco Umbrella SIG
B.Cisco Webex
C.Cisco Identity Services Engine (ISE)
D.Cisco Duo
E.Cisco Meraki Go
AnswersA, D

Umbrella provides the web security and firewall-as-a-service.

Why this answer

Cisco Umbrella SIG and Duo are the core pillars of the Cisco SASE security offering.

23
MCQmedium

What is the primary benefit of using 'SAML' (Security Assertion Markup Language) for cloud application authentication?

A.It prevents unauthorized access to the local network.
B.It enables SSO, reducing the risk associated with password sprawl.
C.It automatically updates the user's password every 30 days.
D.It encrypts all data sent to the cloud provider.
AnswerB

SSO improves security by centralizing authentication and reducing the need for multiple passwords.

Why this answer

SAML enables Single Sign-On (SSO), allowing users to authenticate once and access multiple cloud applications securely.

24
MCQmedium

A user is attempting to access a SaaS application, but the session is blocked by Cisco Cloudlock due to a detected policy violation. Which component is responsible for analyzing the API calls and triggering the remediation?

A.Cloudlock CASB API engine
B.Duo Authentication Proxy
C.AnyConnect SASE client
D.Umbrella SIG proxy
AnswerA

The Cloudlock engine connects via API to SaaS apps to monitor and remediate violations.

Why this answer

Cisco Cloudlock utilizes API-based integration to monitor SaaS environments and enforce security policies, such as DLP or anomaly detection.

25
MCQeasy

Which component of the Cisco SASE architecture provides the primary security enforcement point for remote users browsing the web from untrusted networks?

A.Cisco Umbrella SIG
B.Cisco Firepower Threat Defense (FTD)
C.Cisco Meraki MX
D.Cisco Identity Services Engine (ISE)
AnswerA

Umbrella SIG provides web security, DNS-layer security, and firewall-as-a-service.

Why this answer

The Cisco Umbrella Secure Internet Gateway (SIG) provides the cloud-native security stack for remote users.

26
MCQhard

You are troubleshooting a connection issue where a remote user cannot access a private cloud application via the Cisco Secure Access ZTNA connector. Which step is most likely to resolve the issue?

A.Increase the timeout value on the client browser.
B.Flush the DNS cache on the corporate firewall.
C.Check the health status of the ZTNA connector in the Secure Access dashboard.
D.Reboot the user's laptop.
AnswerC

The connector must have an 'Active' status to route traffic to the private application.

Why this answer

Verifying the connectivity of the ZTNA connector to the private resource is the first diagnostic step to ensure the tunnel is active.

27
Multi-Selectmedium

Which TWO features of Cisco Umbrella assist in preventing data loss?

Select 2 answers
A.DNS query logs
B.Local firewall rules
C.Data Loss Prevention (DLP)
D.Automated DNS updates
E.File inspection (sandboxing)
AnswersC, E

DLP inspects for sensitive data patterns.

Why this answer

Umbrella uses DLP patterns and file inspection to prevent sensitive data from being uploaded to unauthorized locations.

28
MCQmedium

A user is using a managed laptop. How does 'Device Posture' in the Cisco SASE model verify that an antivirus solution is active?

A.By requesting the antivirus vendor to send a status email.
B.By checking the user's browser history.
C.By scanning the user's files remotely.
D.By querying the OS security APIs via the Secure Client agent.
AnswerD

The agent on the endpoint performs the necessary local checks.

Why this answer

The Cisco Secure Client (AnyConnect) periodically checks the system's security posture and reports status to the policy engine before allowing connectivity.

29
Multi-Selecthard

Which THREE factors influence the performance of a SASE deployment?

Select 3 answers
A.Encryption processing overhead
B.The number of users logged into the console
C.Internet circuit quality
D.The version of the office software
E.Distance to the nearest cloud edge node
AnswersA, C, E

Encrypting/decrypting traffic takes time.

Why this answer

Performance is affected by the distance to the cloud node, encryption overhead, and the quality of the internet path.

30
MCQeasy

Which Cisco product facilitates 'Cloud-to-Cloud' security by monitoring activities in SaaS platforms like Microsoft 365?

A.Cisco Cloudlock
B.Cisco Firepower
C.Cisco Duo
D.Cisco Umbrella
AnswerA

Cloudlock is the designated CASB product for SaaS security.

Why this answer

Cisco Cloudlock (part of the Secure Access suite) is a CASB that integrates via API to monitor and protect SaaS applications.

31
MCQmedium

When designing a cloud security architecture, why is 'logging and observability' so critical?

A.To automatically block all incoming traffic.
B.To reduce the cost of cloud storage.
C.To increase the speed of the internet connection.
D.To ensure compliance and enable efficient threat hunting.
AnswerD

Visibility is the foundation of security operations.

Why this answer

Centralized logging provides the necessary data for threat hunting, compliance auditing, and troubleshooting in a distributed cloud environment.

32
MCQmedium

An organization is deploying Cisco Umbrella SIG to enforce Zero Trust access. You must configure the selective decryption policy. Which setting ensures that specific sensitive traffic, such as financial and healthcare sites, is bypassed for inspection to comply with privacy regulations?

A.Apply a 'Transparent Proxy' setting on the local Cisco ASA firewall.
B.Configure a Web Policy rule with a 'Decrypt' action and specify the sensitive categories in the 'Bypass' list.
C.Enable 'HTTPS Inspection' in the Cloud Security global settings and select 'Bypass All' for all categories.
D.Set the 'Block' action for sensitive categories in the Destination Lists.
AnswerB

This is the correct procedural step in Umbrella to exclude traffic from inspection.

Why this answer

Within the Cisco Umbrella dashboard, the SSL Decryption policy allows administrators to define bypass lists for specific categories or domains to prevent sensitive traffic from being decrypted.

33
MCQmedium

A global company needs to ensure that users in different regions have the lowest latency when accessing cloud applications. How should the SASE architecture be configured?

A.Manually configure the proxy settings for each user based on their country.
B.Install an on-premises proxy server in every region.
C.Direct all traffic to a single corporate data center before cloud access.
D.Ensure users are routed through the global anycast network to the nearest Umbrella data center.
AnswerD

Anycast is the key technology that routes users to the optimal node.

Why this answer

Cisco Umbrella uses a globally distributed anycast network, which automatically routes users to the nearest data center, minimizing latency.

34
Multi-Selectmedium

Which THREE factors are typically considered when evaluating 'Device Posture' in a Zero Trust environment?

Select 3 answers
A.The user's home internet speed
B.Disk encryption status
C.Antivirus status
D.The user's favorite website
E.Operating system patch level
AnswersB, C, E

Ensuring data is encrypted on the device is a key security policy.

Why this answer

Posture checks commonly look at OS patches, antivirus status, and disk encryption to determine device health.

35
MCQmedium

Why is 'SSL/TLS Inspection' necessary in a SASE architecture?

A.To allow the security stack to inspect encrypted payloads for threats and sensitive data.
B.To allow the ISP to monitor user traffic.
C.To accelerate the connection for the end user.
D.To replace the need for end-to-end encryption.
AnswerA

Visibility is required to enforce security policies on encrypted traffic.

Why this answer

Without decryption, security tools cannot see the content of encrypted traffic, allowing threats or data leaks to pass undetected.

36
Multi-Selecthard

Which THREE components are critical to consider when designing a 'cloud security reference architecture'?

Select 3 answers
A.Physical server cooling systems
B.Identity and Access Management (IAM)
C.Workload security
D.Secure Internet Gateway (SIG)
E.The brand of the office chair
AnswersB, C, D

Identity is the new perimeter in cloud security.

Why this answer

A complete architecture must account for identity, workload protection, and internet edge security.

37
Multi-Selectmedium

Which TWO are common 'secure access design patterns' in a hybrid cloud?

Select 2 answers
A.Connecting all apps to the local LAN only
B.ZTNA for remote user access
C.Transit gateway inspection for inter-VPC traffic
D.Open access for all traffic
E.Public internet bypass for all traffic
AnswersB, C

This is the current best practice for user access.

Why this answer

Standard patterns include ZTNA for users and secure transit gateways for inter-cloud traffic.

38
MCQhard

You are designing a secure access path for a BYOD device. What is the most effective approach to ensure the device does not compromise the network?

A.Provide the device with a permanent VPN connection.
B.Enforce ZTNA with device posture checks and MFA.
C.Require the device to join the corporate Active Directory domain.
D.Configure an open SSID for BYOD devices.
AnswerB

This combination validates the identity and the security state of the device before granting access.

Why this answer

ZTNA ensures that the device is checked for posture and the user is authenticated before allowing access, regardless of device ownership.

39
MCQhard

When designing a Zero Trust architecture using Cisco Secure Access, how does the 'Device Posture' check specifically influence the access decision for a managed laptop?

A.It switches the user's connection to a VPN tunnel.
B.It forces a mandatory password reset if the device is out of compliance.
C.It checks the user's IP address against a geo-blocking database.
D.It requires the presence of an MDM-enrolled certificate or specific registry key before authorizing the session.
AnswerD

Device posture checks are granular and look for specific configurations like certificates or managed state.

Why this answer

Device posture checks in Cisco Secure Access verify the health and security configuration of the endpoint before granting access to protected applications.

40
MCQhard

You are setting up a secure hybrid cloud environment. How do you implement 'Micro-segmentation' between virtual machines in the same subnet?

A.Rely on the cloud provider's default network ACLs.
B.Place each VM in a different subnet.
C.Configure a VLAN for every virtual machine.
D.Use host-based security policies or a distributed SDN firewall.
AnswerD

Micro-segmentation requires enforcement at the workload level, not the network perimeter.

Why this answer

Micro-segmentation is achieved using host-based firewalls or SDN controllers (like those provided by Cisco Secure Workload/Tetration) to enforce policy at the individual workload level.

41
MCQeasy

What is the primary goal of the 'Cisco SASE' framework?

A.To increase the cost of cloud services.
B.To replace all physical firewalls in the data center.
C.To converge networking and security services into a single cloud-delivered offering.
D.To provide a new type of internet provider service.
AnswerC

The convergence of SD-WAN and SIG is the core of the SASE architecture.

Why this answer

Cisco SASE combines networking and security capabilities into a single cloud-native service to provide secure, optimized access to users wherever they are.

42
MCQmedium

In the context of SASE, what is the primary role of the 'Global Anycast Network'?

A.To hide the internal IP addresses of the users.
B.To manage user credentials across multiple cloud providers.
C.To provide high availability and optimal latency by routing traffic to the nearest security node.
D.To encrypt traffic between the user and the cloud.
AnswerC

This is the core benefit of anycast for SASE performance.

Why this answer

Anycast allows the enterprise to use a single IP address to reach the nearest Umbrella data center, improving performance and reliability.

43
Multi-Selecthard

Which THREE factors should be considered when designing an IaaS security architecture using Cisco Secure Workload (formerly Tetration)?

Select 3 answers
A.Physical switch port mirroring
B.Global firewall rule consolidation
C.Identity-based policy enforcement
D.Application dependency mapping
E.Host-based sensor deployment
AnswersC, D, E

Policies should be tied to workload identity rather than IP addresses.

Why this answer

Secure Workload focuses on visibility, micro-segmentation, and policy enforcement across hybrid clouds.

44
Multi-Selecthard

Which THREE types of information are analyzed by Cisco Secure Workload (Tetration) to enforce micro-segmentation?

Select 3 answers
A.The color of the server rack
B.User identity context
C.Process-level information
D.User's home address
E.Network flow telemetry
AnswersB, C, E

Linking flows to users provides better security context.

Why this answer

Tetration analyzes process information, user context, and network flow data to define policies.

45
MCQmedium

A security architect is designing a SASE solution. What is the significance of 'Identity-Based Segmentation' in this design?

A.It allows for faster internet speeds by bypassing the firewall.
B.It allows for access control based on user identity rather than network topology.
C.It enables automatic IP address assignment for cloud users.
D.It reduces the complexity of managing VLANs.
AnswerB

This is the fundamental shift from traditional network segmentation to identity-centric security.

Why this answer

Identity-based segmentation allows for granular access control, ensuring users can only access applications they are authorized to use, regardless of their location.

46
MCQhard

You are designing a secure remote access solution for a hybrid cloud environment. Which Cisco technology should you implement to replace a traditional VPN while enforcing Zero Trust principles?

A.Cisco Secure Access (ZTNA)
B.Cisco Stealthwatch Cloud
C.Cisco Meraki Client VPN
D.Cisco Firepower VPN
AnswerA

ZTNA provides granular, application-specific access, which is the core of Zero Trust remote access.

Why this answer

Cisco Secure Access (the ZTNA offering) provides per-application access based on identity and posture, replacing the broad network access of a VPN.

47
MCQhard

When implementing a ZTNA solution, which factor is most crucial when defining an 'Application Access Policy'?

A.The identity of the user and the specific application they require.
B.The physical location of the cloud data center.
C.The source IP address of the user's laptop.
D.The user's department in Active Directory.
AnswerA

Zero Trust focuses on user-to-app, not net-to-net connectivity.

Why this answer

In ZTNA, policies must be defined based on the user identity and the specific application, rather than network segments.

Ready to test yourself?

Try a timed practice session using only Cloud Security Architecture questions.