CV0-004 · domain
Security
Security covers identity and access management, network controls, data protection, and compliance in multi-cloud environments. Questions present scenarios requiring selection of AWS, Azure, or GCP services to enforce least privilege, secure data, and meet regulatory standards. You must apply shared responsibility and choose the correct tool for each control objective.
Focused practice
Practice Security questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Security
You must select and configure the correct cloud-native security controls for given scenarios. The most important thing is to correctly apply the shared responsibility model to determine whether the provider or customer handles each security task.
Configuring AWS security groups and network ACLs to control inbound traffic to EC2 instances.
Using Azure Policy and Microsoft Defender for Cloud to enforce HIPAA and PCI DSS compliance.
Implementing AWS IAM roles, policies, and KMS for encryption and access management.
Deploying Web Application Firewalls (WAF) with geographic and IP-based filtering rules.
Watch out for
Common Security exam traps
- ▸Confusing security groups (stateful, instance-level) with network ACLs (stateless, subnet-level) when controlling traffic.
- ▸Assuming cloud providers fully manage compliance for PaaS or IaaS, ignoring customer responsibilities under shared responsibility model.
- ▸Using identity-based policies when resource-based policies are required for cross-account access in AWS.
Question index
All Security questions (121)
Click any question to see the full explanation, or start a practice session above.
Which of the following is a stateless network access control that requires explicit allow rules for both inbound and outbound traffic?
Easy2A cloud operations team is investigating suspicious activity in a production subscription. Logs show that a service principal authenticated successfully from an unexpected country and then enumerated storage accounts. The team needs to shorten the window in which a stolen credential remains usable and receive an alert when anomalous sign-ins occur. Which combination of controls should the team prioritize?
Hard3A cloud administrator needs to audit all API calls made in a GCP project for compliance purposes. Which service should be enabled to log these actions?
Medium4An organization is subject to PCI DSS compliance and must demonstrate that it is meeting security requirements. Which cloud service can aggregate compliance findings and provide a dashboard?
Medium5A company uses Google Cloud Platform and wants to enforce that all Compute Engine instances use a specific Customer-Managed Encryption Key (CMEK) for disk encryption. Which GCP service should be used to enforce this policy?
Hard6A cloud engineer is configuring a web application that must comply with PCI DSS. The application runs on virtual machines in a public cloud. Which of the following security responsibilities falls under the customer's scope according to the shared responsibility model?
Medium7A cloud security team is implementing a zero-trust security model for a microservices application deployed on Azure Kubernetes Service (AKS). The team needs to ensure that all service-to-service communication is authenticated and encrypted, and that access policies are enforced based on service identity rather than network location. Which TWO components should the team implement to achieve these goals? (Choose two.)
Hard8A multinational company uses Google Cloud and needs to ensure that its data cannot be exfiltrated to unauthorized networks even if an attacker obtains valid IAM credentials. The security team wants to define a boundary around specific projects and restrict access to only approved VPC networks and services. Which GCP feature should they implement?
Hard9Which of the following is a best practice for managing secrets in cloud applications?
Easy10An organization uses AWS and wants to control inbound traffic to its EC2 instances. They need a solution that automatically allows response traffic for any permitted inbound request. Which of the following should they use?
Hard11A cloud operations team is reviewing the shared responsibility model for a SaaS customer relationship management application. The team wants to document which security tasks remain the customer's responsibility. Which task is the customer responsible for under the shared responsibility model?
Easy12A financial services firm stores regulated customer records in an Amazon S3 bucket. Auditors require that every object be encrypted at rest with a customer-managed key, that key usage be logged, and that the firm be able to revoke access to the data by disabling the key. Which configuration meets these requirements?
Hard13A multinational enterprise uses Amazon Route 53 for public DNS. A recent incident showed that an attacker changed a registrar's nameserver delegation and redirected traffic to a malicious site. The security team wants to detect unauthorized changes to DNS records and receive alerts when records are modified outside the change-management process. Which combination should the team implement?
Hard14A company is deploying a web application on GCP and needs to protect against OWASP Top 10 threats and DDoS attacks. Which THREE services should be combined to provide comprehensive protection?
Hard15A cloud administrator manages a fleet of Amazon EC2 instances hosting a stateless web tier. The security team requires that any administrative SSH access is logged to a tamper-evident, centralized location, and that the private keys never leave a hardware device. Which approach should the administrator implement?
Medium16A cloud operations team runs a containerized payroll application on Amazon EKS. Compliance requires that the application pod retrieve database credentials at runtime without embedding them in the container image, and that the credentials be rotated automatically every 30 days. Which approach BEST meets these requirements?
Medium17A DevOps team is deploying containerized applications on Kubernetes. They want to ensure containers do not run with root privileges and that host filesystem access is restricted. Which Kubernetes feature should they use?
Medium18A cloud engineer is deploying a containerized workload to a Kubernetes cluster running in a public cloud. The security team requires that the application pods never use long-lived static credentials to access the cloud provider's object storage service. The cluster already runs an OpenID Connect (OIDC) identity provider that the cloud provider trusts. Which approach should the engineer implement to meet this requirement?
Medium19A company uses Azure AD for identity federation with an on-premises Active Directory. They want to enable single sign-on (SSO) for cloud applications using an open standard. Which protocol should they use?
Hard20A financial services company runs a containerized payment application on Google Kubernetes Engine (GKE). A compliance auditor requires that all container images deployed to the cluster be cryptographically verified for integrity and provenance before admission. The security team wants to enforce this at the cluster level without modifying each application's deployment pipeline. Which GKE feature should they implement?
Medium21A cloud architect is designing a DDoS protection strategy for a web application hosted on AWS. The application uses an Application Load Balancer (ALB). Which service provides automatic, always-on DDoS protection at no additional cost?
Hard22A security engineer is reviewing IAM policies and notices a policy that allows all actions on all resources for a user. Which principle of security is being violated?
Medium23A cloud architect is designing identity and access management (IAM) for a multi-cloud environment. The architect wants to enforce least privilege and support federation with an on-premises Active Directory. Which TWO of the following should be implemented? (Select TWO).
Easy24A healthcare company runs a web application on Google Cloud. A security analyst notices that attackers are submitting crafted SQL statements through the application's search form and reading data from the backend database. The company wants to block these requests before they reach the application servers while keeping false positives low for legitimate search traffic. Which service should be implemented?
Easy25A cloud security team is reviewing audit logs and notices that a service account has been used to launch several high-risk API calls that are not part of its normal behavior. Which security control should be implemented to detect such anomalies in real time?
Hard26During a security audit, a cloud engineer discovers that a container image used in production has a known critical vulnerability in a base layer. Which practice should be implemented to prevent this in the future?
Hard27A company is migrating its on-premises applications to a public cloud. The security team wants to ensure that the cloud provider is responsible for physical security of data centers, while the company remains responsible for securing guest operating systems. Which concept does this describe?
Medium28A healthcare organization must protect electronic protected health information stored in a public cloud object storage bucket. Compliance requires encryption at rest with customer-controlled keys and verifiable evidence that data has not been altered. Which TWO controls should be implemented to meet these requirements? (Choose two.)
Medium29A company has deployed a containerized application on a Kubernetes cluster. The security team wants to ensure that containers cannot run as the root user and that the container's root filesystem is read-only. Which Kubernetes security mechanism should be used?
Hard30A security team runs workloads in Microsoft Azure and must ensure that all data stored in Azure SQL Database and Azure Storage accounts is encrypted with customer-managed keys (CMK) rather than platform-managed keys. The compliance officer requires that the organization be able to revoke access to the data by disabling the key, and that key rotation be controlled internally. Which Azure service should the team configure to meet these requirements?
Hard31A security administrator is deploying a web application firewall (WAF) to protect a public-facing web application. The application experiences a high volume of traffic from a specific geographic region that is not part of the target customer base. Which WAF feature would best reduce the attack surface without impacting legitimate users?
Hard32A company's compliance team must provide evidence that their cloud environment meets PCI DSS requirements. Which AWS service can aggregate security findings and automate compliance checks?
Medium33An organization is subject to PCI DSS compliance and must ensure that all data transmitted between its cloud application and users is encrypted. Which encryption method should be enforced?
Medium34An organization needs to store database credentials and API keys securely in the cloud, with automatic rotation every 90 days. Which service should be used?
Medium35A cloud administrator notices that an AWS IAM user has more permissions than necessary. Which principle should be applied to correct this?
Medium36A cloud administrator is deploying a new containerized workload on Google Kubernetes Engine in Google Cloud. The security team requires that the containers run with a non-root user, have a read-only root filesystem where possible, and are prevented from gaining additional Linux capabilities. Which GKE feature should the administrator enable to enforce these restrictions at the pod level?
Easy37A cloud administrator is configuring network ACLs (NACLs) for a VPC subnet. The subnet hosts a web server that must accept HTTP (port 80) and HTTPS (port 443) from the internet, and the server needs to respond to clients. Which TWO rules are required?
Medium38A cloud engineer is deploying a containerized application on Kubernetes. The security team requires that containers run with reduced privileges and that certain capabilities are dropped. Which Kubernetes feature should be used to enforce these requirements?
Medium39A security team needs to enforce multi-factor authentication (MFA) for all users accessing the cloud management console. Which IAM feature should be configured?
Medium40A company's cloud environment uses Azure Active Directory for identity management. They want to allow employees to sign in using their existing on-premises Active Directory credentials without synchronizing passwords to the cloud. Which federation protocol should they use?
Hard41A cloud administrator needs to ensure that a set of AWS EC2 instances can only be accessed via SSH from the corporate office IP range 203.0.113.0/24. Which configuration should the administrator implement?
Medium42A financial services company runs a multi-tenant SaaS application on AWS. Each tenant has dedicated Amazon RDS for MySQL databases. The security team must ensure that data at rest is encrypted with keys that are unique per tenant and that the company can independently audit key usage. Which approach should be used?
Hard43A cloud operations team manages a multi-account AWS environment. Auditors require that every API call made in all accounts be logged to a central location, that logs be immutable for 90 days, and that the logs capture the identity of the caller, the source IP, and the request time. The team wants minimal custom development. Which combination should the team implement?
Medium44A cloud administrator manages a Microsoft Azure subscription. The security team requires that all virtual machines in a resource group be protected by a host-based firewall that filters traffic by port and protocol, independent of any network security group rules. The administrator needs a solution that can be applied directly to the operating system of each VM. Which solution should the administrator implement?
Medium45A cloud administrator manages an AWS environment where developers require temporary, least-privilege access to specific S3 buckets. The administrator wants to avoid creating long-term IAM user credentials and needs the ability to audit who assumed which role and when. Which AWS service should be used to issue short-lived credentials for these developers?
Medium46A company has a requirement to enforce least privilege for its cloud resources. The cloud engineer is configuring IAM policies. Which of the following best describes least privilege?
Medium47A cloud administrator is configuring a Linux virtual machine in Google Cloud. The security policy requires that all administrative access to the VM use short-lived SSH certificates issued by an internal certificate authority, rather than static SSH keys. Which GCP feature should be used to meet this requirement?
Medium48A company is adopting a shared responsibility model for a PaaS cloud deployment. Which THREE responsibilities belong to the customer?
Easy49A cloud architect is designing a container security strategy. Which TWO of the following should be implemented to secure containers? (Choose two.)
Medium50A company stores sensitive customer data in an S3 bucket and must encrypt the data at rest using a key managed by the company (not AWS). Which encryption option should the company use?
Medium51A company is implementing a secrets management solution. The security team wants to ensure that secrets are protected and rotated regularly. Which THREE of the following are best practices for secrets management?
Hard52A company uses AWS and needs to enforce that all S3 buckets are encrypted at rest with customer-managed keys stored in AWS KMS. Which IAM policy condition would ensure this?
Hard53An administrator is configuring access to a cloud management console for a large team. The organization wants to require a second authentication factor for all users and centralize the identity source so that disabling an account in the corporate directory immediately removes cloud access. Which approach should the administrator implement?
Easy54A financial services firm stores regulated customer records in an object storage bucket in a public cloud. A compliance auditor requires that every object be encrypted with a customer-managed key so the firm can revoke access instantly and prove key custody, while still allowing the provider to perform envelope encryption for performance. Which configuration meets these requirements?
Hard55An organization is moving sensitive data to the cloud and must ensure it is encrypted while stored on disk. Which type of encryption should be implemented?
Easy56A company is migrating to a public cloud and wants to understand security responsibilities. According to the shared responsibility model, which of the following is the customer responsible for in an IaaS deployment?
Medium57A company running a critical web application wants to protect against SQL injection and cross-site scripting attacks. The application is behind a load balancer. Which type of service should be deployed to provide this protection?
Hard58A company uses a SaaS application for customer relationship management (CRM). The security team wants to monitor user activities and enforce data loss prevention (DLP) policies. Which type of security tool should be deployed?
Medium59A cloud operations team is hardening a Microsoft Azure subscription that hosts production virtual machines. The security lead wants to ensure that only approved operating system images can be deployed and that any drift from the baseline configuration is automatically detected. Which TWO Azure services should be implemented to meet these goals? (Choose two.)
Medium60A company is migrating to AWS and needs to meet PCI DSS compliance. Which THREE of the following should be implemented? (Choose three.)
Hard61A security analyst is reviewing logs and finds that an unauthorized user accessed a storage blob in a cloud environment. The analyst needs to determine which permissions allowed the access. Which cloud feature provides a detailed view of effective permissions for a user?
Medium62A cloud security team is implementing a secrets management solution for applications running on AWS. They need to automatically rotate database credentials every 30 days and avoid hardcoding secrets. Which service should they use?
Hard63An organization uses multiple SaaS applications and wants to enforce data loss prevention policies and gain visibility into user activity. Which technology should they implement?
Medium64A cloud security team is hardening a Microsoft Azure subscription that hosts production virtual machines. The team must ensure that administrative access to the VMs requires multi-factor authentication and that privileged role assignments are reviewed on a recurring basis. (Choose two.)
Medium65A company is using a SaaS application and wants to gain visibility into user activity and enforce data loss prevention policies. Which technology should be deployed?
Medium66A cloud security engineer is hardening a Kubernetes cluster. Which TWO measures should be implemented to improve container security? (Choose two.)
Medium67A security team discovers that a container image used in production contains a known vulnerability in one of its base image layers. Which action should be taken to remediate this issue?
Medium68A cloud security team is implementing a key management strategy for workloads spread across AWS and Azure. The team wants a single system of record for cryptographic keys, with the ability to import existing keys from on-premises HSMs, enforce automatic annual rotation, and produce immutable audit logs of every key use. Which approach best satisfies these requirements?
Medium69A financial services company stores regulated data in Amazon S3 buckets. A security architect must ensure that objects are encrypted at rest using keys that the company controls, can be rotated on a schedule, and can be audited independently of AWS-managed keys. The keys must not leave AWS hardware security modules in plaintext. Which encryption option should the architect choose?
Hard70A cloud security engineer is implementing a data loss prevention (DLP) strategy for sensitive data stored in Amazon S3. The company must detect and prevent accidental exposure of personally identifiable information (PII) in objects uploaded by users. The engineer needs a solution that automatically scans new objects, identifies PII, and can trigger alerts or block access. Which AWS service should the engineer use?
Hard71A cloud engineer manages a Kubernetes cluster on Google Kubernetes Engine (GKE). An application team reports that a compromised container in the 'payments' namespace attempted to read secrets belonging to the 'analytics' namespace, but the request was denied. The engineer wants to enforce a policy that restricts pod-to-pod traffic so that only pods labeled 'app=frontend' can reach pods labeled 'app=api' on TCP port 8080, while denying all other ingress to the api pods. Which mechanism should the engineer implement?
Medium72A cloud administrator is designing network security for a three-tier application. The web tier must be accessible from the internet, but the application and database tiers should only be reachable from the web tier. Which security group configuration should be used?
Medium73A cloud architect is designing a multi-tier application. The application tier needs to access a database, but the database should not be reachable from the internet. Which network security control should be used?
Medium74An organization wants to ensure that only authenticated users from their corporate Active Directory can access cloud resources. Which federation protocol is most commonly used for this purpose?
Medium75In the shared responsibility model, which of the following is the cloud customer responsible for?
Easy76A company is deploying a cloud-native application that uses containers orchestrated by Kubernetes. The security team wants to enforce the principle of least privilege at the Kubernetes level. Which THREE measures should be implemented? (Choose three.)
Hard77A security administrator needs to store database credentials and API keys securely in AWS. The credentials must be automatically rotated every 90 days. Which service should the administrator use?
Easy78A cloud security team is reviewing a Google Cloud environment. They need to ensure that data stored in Cloud Storage buckets is protected with customer-managed encryption keys and that access to those keys is tightly controlled. Which TWO actions should the team take? (Choose two.)
Hard79A security administrator is configuring a Web Application Firewall (WAF) to protect a public-facing web application. The application experiences a high volume of traffic from certain geographic regions that are not serving customers. Which WAF feature should be used to block this traffic?
Hard80A company uses Azure RBAC to manage access to resources. A user is assigned a Contributor role at the subscription scope. Which of the following is true regarding the scope of this role?
Hard81A cloud administrator needs to grant a developer read-only access to a specific storage bucket in AWS. Which IAM component should the administrator modify?
Easy82A financial services firm runs containerized workloads on a managed Kubernetes service. Auditors require that no container can run as root, that privilege escalation is blocked, and that the policy is enforced at admission time without modifying existing deployment manifests. Which control best meets these requirements?
Hard83A company uses Azure and wants to enforce multi-factor authentication (MFA) for all administrative users. The solution must be centrally managed and apply to all Azure subscriptions. Which approach should be used?
Hard84A company uses Google Cloud Platform (GCP) and wants to enforce that all service accounts used by applications have only the permissions necessary to perform their tasks. Which IAM concept should the administrator apply?
Hard85A cloud engineer is configuring a web application on AWS and needs to ensure that only HTTP and HTTPS traffic from the internet is allowed to reach the EC2 instances. Which AWS service should be used to control inbound traffic at the instance level?
Easy86A security administrator is configuring a web application firewall (WAF) to protect against SQL injection attacks. Which WAF feature should be enabled?
Medium87An organization uses multiple cloud providers and wants to centralize secrets management. Which solution would best meet this requirement?
Medium88An organization wants to audit all API calls made in their AWS account. Which AWS service should be enabled to capture these logs?
Easy89An organization uses Azure and wants to ensure that only authenticated users from its on-premises Active Directory can access cloud resources. The company has Azure AD Connect set up and wants to enable single sign-on (SSO) for cloud applications. Which federation standard should be used?
Medium90Which of the following is the cloud provider's responsibility under the shared responsibility model?
Easy91A security administrator needs to enforce least privilege for a Kubernetes cluster in a cloud environment. Which approach should be used to restrict permissions for pods that need to access the cloud provider's API?
Hard92A company uses AWS and wants to centralize security monitoring across multiple accounts. Which service should they use to aggregate security findings and check compliance against standards like CIS AWS Foundations?
Medium93A cloud security engineer is responsible for an AWS environment that stores regulated data in Amazon S3 buckets. An audit finding states that data at rest in S3 is not encrypted with a customer-managed key, and the organization must retain control over key rotation and access policies. The engineer must implement encryption that satisfies the audit while minimizing changes to existing applications. Which approach should the engineer take?
Hard94A financial services company runs a critical application on Google Cloud. The security team requires that all data at rest in Cloud Storage buckets be encrypted with customer-managed encryption keys (CMEK) that are rotated every 90 days. The company also needs to maintain full control over key lifecycle and revoke access immediately if a key is compromised. Which GCP service should be used to manage these keys?
Medium95Which of the following compliance frameworks is specifically designed for handling healthcare information in the United States?
Easy96A cloud security team is implementing encryption for data at rest using customer-managed keys in a cloud KMS. Which THREE practices should be followed?
Hard97A cloud architect is designing a multi-tenant SaaS application on AWS. Which of the following security responsibilities is the CUSTOMER responsible for under the shared responsibility model?
Easy98A DevOps team deploys a containerized application on Amazon EKS. The security team wants to ensure that containers do not run as root and that read-only root filesystems are enforced. Which Kubernetes mechanism should be used?
Hard99A cloud administrator needs to provide external partners with access to a cloud application using their existing corporate credentials. Which federation protocol should be used?
Medium100A cloud engineer is deploying a containerized application on Amazon EKS. The application pods need to access an Amazon RDS database. The security team wants to avoid storing database credentials in the container image or environment variables and prefers short-lived credentials. Which mechanism should be used?
Hard101Which encryption standard is most commonly used for data at rest in cloud storage services?
Easy102A cloud engineer is configuring an Azure Storage account that holds regulated customer data. The compliance team requires that data is encrypted at rest with customer-managed keys stored in Azure Key Vault, and that key usage is auditable. Which configuration should the engineer apply?
Easy103A company stores sensitive customer data in an Amazon S3 bucket. A security audit reveals that the data is encrypted at rest using SSE-S3. The company now requires that they manage and control the encryption keys themselves, including the ability to rotate and revoke them. Which S3 encryption option should be used?
Easy104A cloud customer is deploying a virtual machine (VM) in a public IaaS environment. According to the shared responsibility model, which of the following security tasks is the customer responsible for?
Easy105A security engineer is designing a data classification policy for a cloud environment. The policy must identify sensitive data, apply appropriate controls, and monitor access. Which THREE of the following should be included in the policy? (Select THREE.)
Hard106Which of the following is a benefit of using a Cloud Access Security Broker (CASB) for SaaS applications?
Easy107A cloud security architect is designing a data protection strategy for a multi-tenant SaaS application hosted in a public cloud. The application stores tenant data in object storage and a managed relational database. Regulators require that each tenant's data be cryptographically isolated so that a key compromise for one tenant cannot expose another tenant's data, and that the organization be able to prove key usage is auditable. Which TWO measures should the architect implement? (Choose two.)
Hard108A DevOps team deploys a containerized application to a Kubernetes cluster. They need to ensure that containers cannot run with privileged access. Which Kubernetes security mechanism should be applied?
Hard109A startup is deploying a web application on AWS and wants to protect it from common Layer 7 attacks such as SQL injection and cross-site scripting. The application runs behind an Application Load Balancer, and the team wants a managed service that can be deployed quickly with minimal configuration. Which AWS service should they use?
Easy110Which of the following is a benefit of using a Web Application Firewall (WAF)?
Easy111A cloud architect is designing a network to protect a web application from common attacks such as SQL injection and cross-site scripting. Which cloud service should be used?
Easy112A security engineer is configuring a network security group (NSG) in Azure to allow inbound HTTPS traffic to a web server. The engineer creates an inbound rule allowing TCP port 443 from the Internet. What must be done to ensure the web server can respond to clients?
Medium113A security engineer is configuring an AWS IAM policy for a new application. The policy must allow the application to read objects from a specific S3 bucket. Which IAM policy element determines whether the action is allowed or denied?
Medium114According to the shared responsibility model, which of the following is the cloud provider responsible for?
Easy115A cloud security team is implementing the principle of least privilege for IAM roles. Which TWO actions are consistent with this principle?
Medium116A security auditor is reviewing the IAM configuration for a cloud account. The auditor finds that a user has permissions to create and delete resources in all services. Which principle of security is being violated?
Medium117Which of the following is a key benefit of using a Cloud Access Security Broker (CASB)?
Easy118A cloud administrator is configuring a CASB (Cloud Access Security Broker) for SaaS applications. Which TWO capabilities should the administrator expect from the CASB? (Choose two.)
Medium119A cloud security team is hardening a Linux virtual machine that hosts a public-facing API in a public cloud. The team wants to reduce the attack surface at the operating system layer and detect unauthorized file changes. Which TWO measures should the team implement? (Choose two.)
Medium120A cloud administrator needs to protect a web application from common attacks such as SQL injection and cross-site scripting (XSS). Which cloud service should be implemented?
Easy121A cloud administrator is configuring an Azure environment for a healthcare application that must comply with HIPAA. Which TWO configurations are required to meet HIPAA security and privacy rules? (Choose two.)
MediumOther domains
All CV0-004 exam domains
Frequently asked questions
- What does the Security domain cover on the CV0-004 exam?
- You must select and configure the correct cloud-native security controls for given scenarios. The most important thing is to correctly apply the shared responsibility model to determine whether the provider or customer handles each security task.
- How many questions are in this domain?
- This page lists all 121 Security questions in the CV0-004 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Security questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.