Courseiva

CCNA Security Questions

75 of 121 questions · Page 1/2 · Security · Answers revealed

1
MCQeasy

Which of the following is a stateless network access control that requires explicit allow rules for both inbound and outbound traffic?

A.Security group
B.Network ACL
C.DDoS protection
D.Web application firewall
AnswerB

NACLs are stateless and require rules for both directions.

Why this answer

Network ACLs (NACLs) are stateless; security groups are stateful.

2
MCQhard

A cloud operations team is investigating suspicious activity in a production subscription. Logs show that a service principal authenticated successfully from an unexpected country and then enumerated storage accounts. The team needs to shorten the window in which a stolen credential remains usable and receive an alert when anomalous sign-ins occur. Which combination of controls should the team prioritize?

A.Shorten the credential lifetime for the service principal and configure risk-based sign-in alerting that triggers on anomalous locations.
B.Grant the service principal contributor rights at the subscription scope and enable multi-factor authentication for all interactive users.
C.Increase the password length for the service principal and enable verbose application logging on the storage accounts.
D.Rotate the service principal secret annually and rely on monthly manual review of stored sign-in logs to identify anomalies.
AnswerA

Reducing the credential lifetime limits how long a stolen secret remains valid, directly shrinking the exposure window. Risk-based sign-in detection flags authentications from atypical locations or impossible travel and can alert or block in near real time, addressing the unexpected-country enumeration. Together these controls target both the duration of exposure and timely detection of the anomaly.

Why this answer

Reducing credential lifetime is the most direct way to bound how long a stolen service principal secret can be abused, since every token issued from it expires on a short schedule. Risk-based sign-in alerting detects unusual locations and impossible travel, delivering the timely notification the team needs. Together they address both the exposure window and the detection gap revealed by the incident.

Exam trap

The trap here is thinking that stronger passwords or broader permissions improve security for a non-interactive service principal, when credential lifetime and anomaly detection are the real levers.

3
MCQmedium

A cloud administrator needs to audit all API calls made in a GCP project for compliance purposes. Which service should be enabled to log these actions?

A.GCP Cloud Audit Logs
B.Azure Monitor
C.GCP Security Command Center
D.AWS CloudTrail
AnswerA

Cloud Audit Logs records Admin Activity, Data Access and System Event entries for every API call in the project, giving the compliance audit trail required. Enabling it satisfies the stem's need to capture all API actions, since these logs are generated automatically per project, folder and organisation.

Why this answer

GCP Cloud Audit Logs is the correct service because it records all API calls and administrative actions in a GCP project, including Admin Activity, Data Access, System Event, and Policy Denied logs. Enabling and exporting these logs to a SIEM or log bucket satisfies the compliance audit requirement for API call visibility.

Exam trap

CV0-004 often tests multi-cloud service recognition, causing candidates to pick a service from the wrong cloud provider (Azure Monitor, AWS CloudTrail) or a security posture tool (SCC) instead of the actual audit logging service.

How to eliminate wrong answers

Option B is wrong because Azure Monitor is a Microsoft Azure service and does not audit GCP API calls. Option C is wrong because Security Command Center is a security posture and threat detection service — it consumes audit logs but is not the logging service that records API calls. Option D is wrong because AWS CloudTrail is the AWS equivalent and does not log GCP activity.

4
MCQmedium

An organization is subject to PCI DSS compliance and must demonstrate that it is meeting security requirements. Which cloud service can aggregate compliance findings and provide a dashboard?

A.AWS CloudTrail
B.AWS Security Hub
C.AWS Shield
D.AWS Config
AnswerB

AWS Security Hub aggregates findings across AWS accounts and services, mapping them to standards including PCI DSS, then surfaces compliance status in a single dashboard. This directly satisfies the requirement to demonstrate adherence to PCI DSS security controls through consolidated, continuously updated evidence rather than manual reporting.

Why this answer

AWS Security Hub aggregates security findings from multiple AWS services and provides a compliance dashboard.

5
MCQhard

A company uses Google Cloud Platform and wants to enforce that all Compute Engine instances use a specific Customer-Managed Encryption Key (CMEK) for disk encryption. Which GCP service should be used to enforce this policy?

A.IAM Conditions
B.Organization Policies
C.Cloud Security Command Center
D.Cloud Key Management Service
AnswerB

Organization policies can enforce that only CMEK-protected disks are allowed.

Why this answer

Organization Policies (formerly known as 'Constraints') allow administrators to define and enforce guardrails for Google Cloud resources at the hierarchy level. The specific constraint `compute.requireCsekEncryption` (or the newer CMEK-based equivalent) can be applied to a folder or project to mandate that all Compute Engine disks use a Customer-Managed Encryption Key, rejecting any instance creation or disk attachment that does not comply.

Exam trap

The trap here is that candidates often confuse the key management service (which creates keys) with the policy enforcement service (which enforces their usage).

How to eliminate wrong answers

Option A is wrong because IAM Conditions control access to resources based on attributes like time or resource tags, but they cannot enforce encryption key requirements on Compute Engine instances. Option C is wrong because Cloud Security Command Center is a security and risk dashboard that provides visibility and threat detection, not a policy enforcement mechanism for resource configuration. Option D is wrong because Cloud Key Management Service is the service that creates, manages, and stores encryption keys, but it does not enforce policies that require their use on Compute Engine disks.

6
MCQmedium

A cloud engineer is configuring a web application that must comply with PCI DSS. The application runs on virtual machines in a public cloud. Which of the following security responsibilities falls under the customer's scope according to the shared responsibility model?

A.Replacing failed physical drives in the storage array
B.Patching the guest operating system of the virtual machines
C.Configuring the physical network firewall
D.Applying hypervisor patches
AnswerB

Patching the guest operating system falls to the customer because infrastructure-as-a-service places OS-level maintenance squarely on the tenant, not the provider. PCI DSS requires timely security updates on systems handling cardholder data, and the hypervisor, physical hosts and network fabric remain the provider's responsibility under this model.

Why this answer

In the shared responsibility model, the customer is responsible for patching the guest OS, while the cloud provider manages the physical infrastructure and hypervisor.

7
Multi-Selecthard

A cloud security team is implementing a zero-trust security model for a microservices application deployed on Azure Kubernetes Service (AKS). The team needs to ensure that all service-to-service communication is authenticated and encrypted, and that access policies are enforced based on service identity rather than network location. Which TWO components should the team implement to achieve these goals? (Choose two.)

Select 2 answers
A.Open Service Mesh (OSM) with mutual TLS (mTLS) enabled
B.Azure Active Directory (Azure AD) workload identities
C.Network Security Groups (NSGs) with service tags
D.Azure Bastion for secure remote access to AKS nodes
E.Azure Firewall with network rules based on IP addresses
AnswersA, B

Open Service Mesh (OSM) is a lightweight service mesh that provides mTLS for service-to-service communication, encrypting traffic and authenticating service identities. It enforces access policies based on service accounts, aligning with zero-trust principles. OSM integrates natively with AKS and can leverage Azure AD workload identities for certificate management, making it essential for encrypted and authenticated communication.

Why this answer

A zero-trust model for microservices requires strong service identities and encrypted, authenticated communication. Azure AD workload identities provide the identity plane, allowing services to authenticate using Azure AD tokens. Open Service Mesh with mTLS provides the data plane encryption and enforces access policies based on those identities.

Together, they ensure that service-to-service communication is both authenticated and encrypted, independent of network location.

Exam trap

The trap here is assuming that network-layer controls like firewalls or NSGs can provide identity-based authentication and encryption for microservices.

8
MCQhard

A multinational company uses Google Cloud and needs to ensure that its data cannot be exfiltrated to unauthorized networks even if an attacker obtains valid IAM credentials. The security team wants to define a boundary around specific projects and restrict access to only approved VPC networks and services. Which GCP feature should they implement?

A.VPC firewall rules with egress deny
B.Cloud Armor security policies
C.VPC Service Controls
D.Cloud Identity-Aware Proxy (IAP)
AnswerC

VPC Service Controls create a service perimeter around Google Cloud projects and resources, restricting access to only approved VPC networks and preventing data exfiltration even with valid credentials. This directly addresses the requirement to block exfiltration despite compromised IAM credentials, because the perimeter enforces context-aware access independent of IAM permissions.

Why this answer

VPC Service Controls establish a security perimeter around Google Cloud projects and services, restricting access to authorized VPC networks and preventing data exfiltration even when IAM credentials are compromised. The other options protect application access, VM egress, or edge traffic, none of which create the service-level boundary needed to stop API-based data movement.

Exam trap

The trap here is assuming that IAM and firewall rules are sufficient to stop exfiltration, when an attacker with valid credentials can use service APIs that bypass VPC-level controls unless a service perimeter is in place.

9
MCQeasy

Which of the following is a best practice for managing secrets in cloud applications?

A.Embed secrets in application code
B.Store secrets in environment variables
C.Use a cloud secrets manager with automatic rotation
D.Share secrets via email
AnswerC

A cloud secrets manager with automatic rotation satisfies the core requirement by storing credentials outside application code and rotating them on a defined schedule, limiting exposure if leaked. This removes hardcoded secrets from repositories and configuration files, which is the primary risk the question targets.

Why this answer

Using a cloud secrets manager with automatic rotation is the best practice because it centralizes secret storage, encrypts secrets at rest and in transit, and automates rotation to reduce the risk of credential leakage. Services like AWS Secrets Manager, Azure Key Vault, and Google Secret Manager provide fine-grained access control and audit logging, ensuring secrets are not exposed in code or configuration files.

Exam trap

CV0-004 often tests the misconception that environment variables are secure; candidates may choose them over a dedicated secrets manager, not realizing that environment variables can be exposed and lack rotation.

How to eliminate wrong answers

Option A is wrong because embedding secrets in application code exposes them in source control, build artifacts, and logs, making them vulnerable to unauthorized access. Option B is wrong because environment variables can be inadvertently exposed through debugging interfaces, process listings, or logs, and they lack encryption and rotation capabilities. Option D is wrong because sharing secrets via email is insecure, as email is often unencrypted and can be intercepted or accessed by unauthorized parties.

10
MCQhard

An organization uses AWS and wants to control inbound traffic to its EC2 instances. They need a solution that automatically allows response traffic for any permitted inbound request. Which of the following should they use?

A.DDoS protection
B.Web Application Firewall
C.Security groups
D.Network ACLs
AnswerC

Security groups are stateful: they automatically permit return traffic for any inbound connection you allow, so no separate outbound rule is needed. This satisfies the requirement that response traffic be allowed automatically. Network ACLs are stateless and would require explicit inbound and outbound rules.

Why this answer

AWS security groups are stateful virtual firewalls that automatically allow return traffic for any permitted inbound request, regardless of outbound rules. This stateful behavior means that if an inbound request is allowed, the response is automatically permitted, satisfying the requirement. Network ACLs, by contrast, are stateless and require explicit rules for both directions.

Exam trap

The trap is confusing security groups with network ACLs; candidates often pick NACLs because they sound like firewalls, but only security groups are stateful and automatically allow return traffic for permitted inbound requests.

How to eliminate wrong answers

Option A is wrong because DDoS protection (e.g., AWS Shield) mitigates volumetric attacks and does not control per-instance inbound traffic or manage return traffic. Option B is wrong because a Web Application Firewall (AWS WAF) filters HTTP/HTTPS requests at layer 7 based on web exploit patterns, not general inbound traffic with automatic return traffic handling. Option D is wrong because Network ACLs are stateless — they require separate inbound and outbound rules, so return traffic is not automatically allowed unless explicitly configured.

11
MCQeasy

A cloud operations team is reviewing the shared responsibility model for a SaaS customer relationship management application. The team wants to document which security tasks remain the customer's responsibility. Which task is the customer responsible for under the shared responsibility model?

A.Patching the hypervisor that hosts the SaaS application's virtual machines.
B.Managing user identities, access permissions, and authentication policies within the SaaS application.
C.Maintaining the physical security controls at the data center hosting the SaaS platform.
D.Applying firmware updates to the storage arrays that back the SaaS application's database.
AnswerB

Identity and access management for the customer's own users remains a customer responsibility in every cloud service model, including SaaS. The provider secures the application infrastructure, but the customer decides who can log in, what roles they hold, and how authentication is enforced. Weak access controls on the customer side are a leading cause of SaaS data breaches.

Why this answer

Under the shared responsibility model, the provider secures the cloud infrastructure while the customer secures what they put in the cloud. For SaaS, that means the customer owns data classification, user identity, access management, and authentication configuration. Physical security, hypervisor patching, and hardware firmware all fall to the provider because they sit below the customer's reach.

Exam trap

The trap here is conflating infrastructure-layer duties such as hypervisor or firmware patching with customer duties, which in SaaS are limited to data and identity governance.

12
MCQhard

A financial services firm stores regulated customer records in an Amazon S3 bucket. Auditors require that every object be encrypted at rest with a customer-managed key, that key usage be logged, and that the firm be able to revoke access to the data by disabling the key. Which configuration meets these requirements?

A.Configure default bucket encryption with SSE-S3 and enable S3 server access logging on the bucket.
B.Configure default bucket encryption with SSE-KMS using an AWS-managed key and enable KMS key rotation every year.
C.Enable S3 Object Lock in compliance mode and require SSE-C headers on every PUT request.
D.Configure default bucket encryption with SSE-KMS using a customer-managed AWS KMS key and enable CloudTrail data events for the bucket.
AnswerD

SSE-KMS with a customer-managed key gives the firm control over the key, and disabling that key immediately blocks decryption of all objects, satisfying revocation. AWS KMS logs every cryptographic operation to CloudTrail, and enabling CloudTrail data events captures object-level API activity on the bucket, providing the required usage evidence for auditors.

Why this answer

The scenario demands a customer-managed key that the firm can disable to revoke access, plus logging of key usage. SSE-KMS with a customer-managed AWS KMS key satisfies the key control because disabling the key blocks decryption, and CloudTrail captures KMS cryptographic operations as well as S3 data events. AWS-managed keys, SSE-S3, and SSE-C all lack the customer-controlled revocation and audit characteristics required.

Exam trap

The trap here is treating any server-side encryption as equivalent, when only a customer-managed KMS key can be disabled to revoke data access and is fully logged.

13
MCQhard

A multinational enterprise uses Amazon Route 53 for public DNS. A recent incident showed that an attacker changed a registrar's nameserver delegation and redirected traffic to a malicious site. The security team wants to detect unauthorized changes to DNS records and receive alerts when records are modified outside the change-management process. Which combination should the team implement?

A.Enable Route 53 query logging and create a CloudWatch alarm on the number of NXDOMAIN responses.
B.Create a Route 53 Resolver query log configuration and export logs to Amazon S3 for long-term retention.
C.Enable AWS CloudTrail and create an EventBridge rule that matches Route 53 ChangeResourceRecordSets API calls and routes them to an alerting target.
D.Configure DNSSEC signing on the hosted zone and publish the DS record with the registrar.
AnswerC

Route 53 record changes are control-plane operations recorded by CloudTrail, including the caller identity, source IP, and request parameters. An EventBridge rule that matches the ChangeResourceRecordSets event pattern can trigger an SNS topic or ticketing system immediately, giving the team detection and alerting for out-of-process modifications.

Why this answer

Detecting unauthorized record modification requires visibility into the Route 53 control plane. CloudTrail records ChangeResourceRecordSets calls with the identity and parameters, and an EventBridge rule matching that event pattern can alert the team in near real time. Query logging, Resolver logs, and DNSSEC address resolution behavior or response integrity rather than change detection and alerting.

Exam trap

The trap here is equating DNS query logging with change monitoring, when only CloudTrail captures the API calls that actually modify records.

14
Multi-Selecthard

A company is deploying a web application on GCP and needs to protect against OWASP Top 10 threats and DDoS attacks. Which THREE services should be combined to provide comprehensive protection?

Select 3 answers
A.Cloud Load Balancing
B.Cloud NAT
C.Cloud CDN
D.Cloud VPN
E.Cloud Armor
AnswersA, C, E

Distributes traffic and integrates with Cloud Armor.

Why this answer

Cloud Load Balancing (A) is correct because it distributes incoming traffic across multiple backend instances, providing inherent DDoS resilience by absorbing and scaling with attack traffic. It also integrates directly with Cloud Armor to enforce OWASP Top 10 web application firewall (WAF) rules, such as SQL injection and XSS protections, at the edge before traffic reaches the application.

Exam trap

The trap here is that candidates often confuse similar network services (like NAT gateways or VPN gateways) as security services for inbound traffic, but they are designed for outbound connectivity and encrypted tunnels, not for application-layer threat detection or DDoS mitigation.

15
MCQmedium

A cloud administrator manages a fleet of Amazon EC2 instances hosting a stateless web tier. The security team requires that any administrative SSH access is logged to a tamper-evident, centralized location, and that the private keys never leave a hardware device. Which approach should the administrator implement?

A.Store SSH private keys in AWS Secrets Manager and retrieve them at instance boot via user data.
B.Use AWS Systems Manager Session Manager with an EC2 instance profile and log sessions to Amazon CloudWatch Logs and S3.
C.Deploy a bastion host with SSH certificate authority and forward all session logs to a syslog server.
D.Configure EC2 key pairs and rotate them every 30 days using AWS Lambda and EventBridge.
AnswerB

Session Manager provides shell access through the Systems Manager agent without opening inbound SSH ports or distributing private keys. Sessions can be recorded and streamed to CloudWatch Logs and S3 with object lock for tamper evidence, satisfying both the hardware-key and centralized-logging requirements.

Why this answer

Session Manager uses the Systems Manager agent and IAM instance profiles to broker shell access, so no inbound SSH port or private key distribution is required. Session logging to CloudWatch Logs and S3 with retention controls provides the tamper-evident, centralized audit trail. Together these meet both the key custody and logging requirements without exposing credentials.

Exam trap

The trap here is assuming that storing SSH keys in a managed secret store or rotating them satisfies a requirement that private keys never leave a hardware device.

16
MCQmedium

A cloud operations team runs a containerized payroll application on Amazon EKS. Compliance requires that the application pod retrieve database credentials at runtime without embedding them in the container image, and that the credentials be rotated automatically every 30 days. Which approach BEST meets these requirements?

A.Create an IAM role for the service account and let the application call the database with IAM authentication credentials that never expire.
B.Mount the credentials as a Kubernetes Secret created from a base64-encoded manifest stored in the Git repository.
C.Store the credentials in AWS Secrets Manager and use the AWS Secrets Manager and Config Provider for Secrets Store CSI Driver to inject them into the pod.
D.Inject the credentials as environment variables through the pod spec, referencing values held in an encrypted Amazon S3 bucket.
AnswerC

The Secrets Store CSI Driver with the AWS provider mounts Secrets Manager values directly into the pod as files, so nothing is baked into the image. Secrets Manager supports native rotation schedules, including every 30 days, and the auto-rotate feature refreshes the mounted files without a pod restart. This satisfies both the runtime retrieval and automatic rotation requirements.

Why this answer

The requirement is runtime retrieval of database credentials plus automatic 30-day rotation without embedding secrets in the image. A secrets manager with native rotation integrated into the pod through the Secrets Store CSI Driver delivers both, mounting values as files and refreshing them on schedule. Base64 secrets, environment variables, and IAM role credentials each miss either the rotation or the runtime-injection aspect of the scenario.

Exam trap

The trap here is assuming that base64-encoded Kubernetes Secrets or environment variables provide secure secret handling, when they actually expose plaintext credentials and offer no rotation.

17
MCQmedium

A DevOps team is deploying containerized applications on Kubernetes. They want to ensure containers do not run with root privileges and that host filesystem access is restricted. Which Kubernetes feature should they use?

A.Service accounts
B.ConfigMaps
C.Network policies
D.Pod Security Standards
AnswerD

Pod Security Standards define restricted, baseline and privileged profiles enforced via Pod Security Admission. The restricted profile blocks root execution and host filesystem mounts, directly satisfying both the non-root and host-access constraints without custom policy authoring.

Why this answer

Pod Security Standards (PSS) define three profiles — Privileged, Baseline, and Restricted — that control whether pods can run as root, use host namespaces, access the host filesystem, or use privileged capabilities. Enforcing the Restricted profile via Pod Security Admission (PSA) directly prevents root execution and restricts hostPath/host filesystem access. This is the native Kubernetes mechanism for pod-level security hardening.

Exam trap

The trap is conflating network-level controls (Network Policies) or identity controls (Service Accounts) with workload security controls — candidates pick Network Policies because 'restricting access' sounds security-related, but it does not address root privileges or host filesystem mounts.

How to eliminate wrong answers

Option A is wrong because Service Accounts provide an identity for pods to authenticate to the Kubernetes API and access resources — they do not restrict root privileges or host filesystem access. Option B is wrong because ConfigMaps store non-sensitive configuration data as key-value pairs and have no security enforcement capability. Option C is wrong because Network Policies control ingress/egress traffic between pods at the network layer (L3/L4) and do not govern process privileges or filesystem mounts.

18
MCQmedium

A cloud engineer is deploying a containerized workload to a Kubernetes cluster running in a public cloud. The security team requires that the application pods never use long-lived static credentials to access the cloud provider's object storage service. The cluster already runs an OpenID Connect (OIDC) identity provider that the cloud provider trusts. Which approach should the engineer implement to meet this requirement?

A.Configure an IAM role with a trust policy scoped to the cluster's OIDC provider and annotate the Kubernetes service account so pods receive short-lived tokens.
B.Enable basic authentication on the Kubernetes API server and issue each pod a static service account token stored in a durable Secret.
C.Deploy a sidecar container that holds a username and password for the object storage service and proxies all requests from the application container.
D.Store the object storage access key and secret key in a Kubernetes Secret and mount it into the pod as environment variables.
AnswerA

This is exactly what IRSA-style workload identity federation provides: the cloud IAM role trusts the cluster's OIDC issuer, and the annotated service account lets pods exchange a projected service account token for temporary cloud credentials. No static keys exist anywhere, tokens expire automatically, and access is scoped per service account, satisfying the no-long-lived-credentials requirement cleanly.

Why this answer

Federating the Kubernetes service account with the cloud IAM role through the cluster's OIDC provider lets pods obtain short-lived, automatically rotated credentials scoped to a single workload. Because no secret key material is ever stored in the cluster, the requirement that pods never use long-lived static credentials is met, and least privilege is enforced per service account rather than shared cluster-wide.

Exam trap

The trap here is assuming that storing credentials in a Kubernetes Secret makes them safe, when Secrets are merely base64-encoded and remain long-lived static credentials.

19
MCQhard

A company uses Azure AD for identity federation with an on-premises Active Directory. They want to enable single sign-on (SSO) for cloud applications using an open standard. Which protocol should they use?

A.OAuth 2.0
B.SAML 2.0
C.LDAP
D.Kerberos
AnswerB

SAML 2.0 is an open OASIS standard for exchanging authentication and authorisation data, letting Microsoft Entra ID act as identity provider and issue signed assertions to cloud applications. This satisfies the stem's federation requirement with on-premises Active Directory, delivering browser-based SSO without exposing credentials to each application.

Why this answer

SAML (Security Assertion Markup Language) and OIDC (OpenID Connect) are open standards for federation. SAML is commonly used for SSO with Azure AD. OAuth is for authorization, not authentication.

LDAP is a directory protocol. Kerberos is for on-premises.

20
MCQmedium

A financial services company runs a containerized payment application on Google Kubernetes Engine (GKE). A compliance auditor requires that all container images deployed to the cluster be cryptographically verified for integrity and provenance before admission. The security team wants to enforce this at the cluster level without modifying each application's deployment pipeline. Which GKE feature should they implement?

A.VPC Service Controls
B.Container Analysis
C.Shielded GKE Nodes
D.Binary Authorization
AnswerD

Binary Authorization is a GKE-native admission controller that enforces attestation-based policies on container images at deploy time. It verifies cryptographic signatures produced by trusted attestors before allowing a pod to be created. This satisfies the auditor's requirement for integrity and provenance verification without touching individual pipelines, since enforcement happens centrally on the cluster's admission webhook.

Why this answer

Binary Authorization is the GKE feature purpose-built to enforce that only images signed by trusted attestors can be deployed. Because enforcement occurs through the cluster admission controller, the policy applies centrally without requiring changes to each pipeline. The other options address network perimeters, image metadata scanning, or node hardening, none of which cryptographically verify image provenance at admission time.

Exam trap

The trap here is confusing image scanning tools like Container Analysis with admission enforcement mechanisms — scanning reports findings, while Binary Authorization actually blocks non-compliant images.

21
MCQhard

A cloud architect is designing a DDoS protection strategy for a web application hosted on AWS. The application uses an Application Load Balancer (ALB). Which service provides automatic, always-on DDoS protection at no additional cost?

A.AWS WAF
B.AWS Network Firewall
C.AWS Shield Standard
D.AWS Shield Advanced
AnswerC

AWS Shield Standard is enabled automatically on all AWS accounts and protects against common network and transport layer DDoS attacks at no extra charge. It defends the ALB without configuration, satisfying the always-on, zero-cost constraint.

Why this answer

AWS Shield Standard provides automatic protection against common DDoS attacks for all AWS customers at no additional cost.

22
MCQmedium

A security engineer is reviewing IAM policies and notices a policy that allows all actions on all resources for a user. Which principle of security is being violated?

A.Least privilege
B.Separation of duties
C.Need to know
D.Defense in depth
AnswerA

Least privilege requires granting only the permissions needed for a user's tasks. A policy allowing all actions on all resources grants unrestricted access, directly violating that principle by exceeding any legitimate job function's required scope.

Why this answer

The principle of least privilege states that users should be granted only the minimum permissions necessary to perform their job functions. A policy allowing all actions on all resources grants far more access than needed, directly violating this principle. This is a classic example of an overly permissive IAM policy.

Exam trap

The trap is confusing least privilege with need to know — both limit access, but least privilege is about the minimum permissions to do the job, while need to know is about limiting information access. The wildcard policy is a textbook least-privilege violation.

How to eliminate wrong answers

Option B is wrong because separation of duties requires dividing critical tasks among multiple people to prevent fraud or error — it is not about the scope of a single user's permissions. Option C is wrong because need to know is about limiting access to information on a need-to-know basis, which is related but distinct from the broader permission scope addressed by least privilege. Option D is wrong because defense in depth is about layering multiple security controls (e.g., firewalls, IDS, encryption) so that no single failure compromises the system — it does not describe the over-permissioning of a single identity.

23
Multi-Selecteasy

A cloud architect is designing identity and access management (IAM) for a multi-cloud environment. The architect wants to enforce least privilege and support federation with an on-premises Active Directory. Which TWO of the following should be implemented? (Select TWO).

Select 2 answers
A.Storing shared credentials in application code
B.Assigning full administrator roles to all users
C.Disabling multi-factor authentication (MFA)
D.Using service accounts for application authentication
E.Federation using SAML
AnswersD, E

Service accounts provide dedicated identities with minimal permissions for apps.

Why this answer

Federation with SAML allows SSO from on-prem AD, and service accounts provide non-human identities for applications, both supporting least privilege by granting only necessary permissions.

24
MCQeasy

A healthcare company runs a web application on Google Cloud. A security analyst notices that attackers are submitting crafted SQL statements through the application's search form and reading data from the backend database. The company wants to block these requests before they reach the application servers while keeping false positives low for legitimate search traffic. Which service should be implemented?

A.Cloud Armor security policy with a preconfigured WAF rule for SQL injection attached to the backend service.
B.Cloud IDS endpoint deployed in the application subnet to detect intrusion attempts.
C.VPC Service Controls perimeter around the database project to restrict data exfiltration.
D.Private Service Connect endpoint that exposes the database only to the application's VPC.
AnswerA

Cloud Armor inspects incoming requests at the edge and can apply preconfigured WAF rules, including the SQL injection signature set, before traffic reaches the backend. Rules can run in preview mode first so the team tunes sensitivity and reduces false positives on legitimate search strings. This directly blocks the crafted statements at the perimeter.

Why this answer

The attack arrives as HTTP requests carrying SQL syntax, so the control must inspect request content at the edge. Cloud Armor with a preconfigured WAF rule for SQL injection evaluates requests against the backend service and can block matching traffic, with preview mode available to tune sensitivity. VPC Service Controls, Cloud IDS, and Private Service Connect operate at network or detection layers and cannot stop the payload.

Exam trap

The trap here is assuming that any Google Cloud network security service inspects application payloads, when only Cloud Armor evaluates HTTP request content for SQL injection signatures.

25
MCQhard

A cloud security team is reviewing audit logs and notices that a service account has been used to launch several high-risk API calls that are not part of its normal behavior. Which security control should be implemented to detect such anomalies in real time?

A.Enable API audit logging
B.Implement an anomaly detection service
C.Use a static IAM policy
D.Configure a network ACL
AnswerB

Anomaly detection establishes behavioural baselines for service accounts and flags deviations, such as unusual high-risk API calls, in real time. This satisfies the requirement to detect abnormal activity as it occurs rather than relying on static rules or periodic review.

Why this answer

Anomaly detection services (such as Amazon GuardDuty, Azure Defender, or Google Cloud Security Command Center) use machine learning and behavioral baselines to identify unusual API activity from service accounts in near real time. Since the question specifies detecting deviations from normal behavior, a behavioral analytics control is required rather than passive logging or static policy enforcement.

Exam trap

CV0-004 often tests the distinction between detective controls that merely log (audit logging) and those that actively analyze behavior (anomaly detection) — candidates pick logging because it sounds like 'detection.'

How to eliminate wrong answers

Option A is wrong because API audit logging (e.g., CloudTrail, Activity Log) only records events for later review — it does not analyze or alert on anomalous patterns in real time. Option C is wrong because a static IAM policy defines permitted actions but cannot detect misuse of legitimately granted permissions or behavioral drift. Option D is wrong because a network ACL is a stateless subnet-level packet filter that operates at Layers 3/4 and has no visibility into API semantics or user behavior.

26
MCQhard

During a security audit, a cloud engineer discovers that a container image used in production has a known critical vulnerability in a base layer. Which practice should be implemented to prevent this in the future?

A.Enable Kubernetes pod security policies
B.Use only official images from Docker Hub
C.Perform container image scanning during CI/CD
D.Implement network segmentation
AnswerC

Scanning images in CI/CD catches vulnerable base layers before deployment, so the pipeline fails the build rather than letting the flaw reach production. This directly satisfies the stem's requirement to prevent known critical vulnerabilities recurring in future container images.

Why this answer

Container image scanning during CI/CD integrates security checks into the build pipeline, automatically detecting vulnerabilities in base layers and dependencies before deployment. This shift-left approach prevents vulnerable images from reaching production by failing the build or alerting teams. It is the most effective practice to prevent known vulnerabilities in base layers from being deployed.

Exam trap

CV0-004 often tests the confusion between runtime security controls (like pod security policies) and build-time security practices (like image scanning), leading candidates to choose runtime measures for preventing vulnerable images.

How to eliminate wrong answers

Option A is wrong because Kubernetes pod security policies (now deprecated in favor of Pod Security Admission) control runtime privileges and access, not image vulnerabilities. Option B is wrong because using only official Docker Hub images does not guarantee they are vulnerability-free; official images can still contain vulnerable base layers or outdated packages. Option D is wrong because network segmentation limits lateral movement but does not prevent the deployment of vulnerable images; it addresses runtime network isolation, not image security.

27
MCQmedium

A company is migrating its on-premises applications to a public cloud. The security team wants to ensure that the cloud provider is responsible for physical security of data centers, while the company remains responsible for securing guest operating systems. Which concept does this describe?

A.Least privilege principle
B.Zero Trust architecture
C.Shared responsibility model
D.Defense in depth
AnswerC

The shared responsibility model splits security duties by layer: the provider secures the physical data centres, hardware and hypervisor, while the customer secures everything above, including guest operating systems, patches and identity. This directly satisfies the stem's requirement that the company retains guest OS responsibility while the provider handles physical security.

Why this answer

The shared responsibility model defines the division of security responsibilities between the cloud provider and the customer. The provider is responsible for security 'of' the cloud (e.g., physical data centers), while the customer is responsible for security 'in' the cloud (e.g., guest OS, applications). This matches the scenario where the provider handles physical security and the company secures guest operating systems.

Exam trap

CV0-004 often tests the confusion between the shared responsibility model and other security concepts like least privilege or defense in depth, expecting candidates to identify the model that explicitly divides responsibilities.

How to eliminate wrong answers

Option A is wrong because least privilege is about granting minimal permissions, not about dividing responsibilities between provider and customer. Option B is wrong because Zero Trust is a security model that assumes no implicit trust, focusing on continuous verification, not on responsibility division. Option D is wrong because defense in depth involves multiple layers of security controls, not the specific split of responsibilities between cloud provider and customer.

28
Multi-Selectmedium

A healthcare organization must protect electronic protected health information stored in a public cloud object storage bucket. Compliance requires encryption at rest with customer-controlled keys and verifiable evidence that data has not been altered. Which TWO controls should be implemented to meet these requirements? (Choose two.)

Select 2 answers
A.Apply a bucket policy that denies delete operations to all principals except a designated break-glass role.
B.Enable object versioning on the bucket to retain prior versions of every object.
C.Enable object lock in compliance mode with a retention period aligned to the records retention policy.
D.Configure server-side encryption using a customer-managed key stored in the cloud provider's key management service.
E.Enable cross-region replication so that a second copy of every object exists in another region.
AnswersC, D

Object lock in compliance mode makes objects immutable for the retention period, and even the root account cannot delete or alter them. This provides verifiable evidence that stored records have not been changed, which satisfies the tamper-evidence requirement. Combined with customer-managed encryption keys, it delivers both confidentiality and integrity assurance for regulated health data.

Why this answer

Encryption at rest with a customer-managed key keeps cryptographic control with the organization, while object lock in compliance mode guarantees immutability that even privileged accounts cannot override. Together they deliver confidentiality and verifiable integrity for regulated health records. Versioning, restrictive bucket policies, and cross-region replication improve durability or reduce risk but cannot prove that data remains unaltered.

Exam trap

The trap here is treating versioning or replication as tamper-evidence, when only compliance-mode object lock prevents modification by any principal including the account root.

29
MCQhard

A company has deployed a containerized application on a Kubernetes cluster. The security team wants to ensure that containers cannot run as the root user and that the container's root filesystem is read-only. Which Kubernetes security mechanism should be used?

A.Pod Security Standards
B.Network policies
C.Seccomp profiles
D.Resource quotas
AnswerA

Pod Security Standards define the restricted profile, which sets runAsNonRoot and readOnlyRootFilesystem enforcement via the securityContext, satisfying both constraints. Applied through namespace labels or admission control, they block root execution and writable root filesystems at pod admission.

Why this answer

Pod Security Standards (PSS) are the built-in Kubernetes mechanism for enforcing pod-level security policies, including the 'restricted' profile which requires runAsNonRoot and readOnlyRootFilesystem. PSS replaced the deprecated PodSecurityPolicy and is enforced via namespace labels (pod-security.kubernetes.io/enforce). This directly addresses both requirements: preventing root execution and enforcing a read-only root filesystem.

Exam trap

CV0-004 often tests the confusion between Pod Security Standards (which govern pod security context like runAsNonRoot) and Network Policies (which govern traffic), so candidates who focus on 'security' generically may pick the wrong control.

How to eliminate wrong answers

Option B is wrong because Network policies only control ingress/egress traffic between pods and do not govern container user IDs or filesystem mount options. Option C is wrong because Seccomp profiles restrict which system calls a container can make, not the user identity or filesystem writability. Option D is wrong because Resource quotas limit CPU, memory, and object counts within a namespace, having no bearing on security context settings like runAsNonRoot or readOnlyRootFilesystem.

30
MCQhard

A security team runs workloads in Microsoft Azure and must ensure that all data stored in Azure SQL Database and Azure Storage accounts is encrypted with customer-managed keys (CMK) rather than platform-managed keys. The compliance officer requires that the organization be able to revoke access to the data by disabling the key, and that key rotation be controlled internally. Which Azure service should the team configure to meet these requirements?

A.Azure Information Protection labels applied to the database and storage resources to classify the data.
B.Azure Confidential Computing with SGX-enabled virtual machines hosting the SQL and storage workloads.
C.Azure Key Vault, storing the RSA keys and granting the SQL and Storage resources access via managed identities.
D.Azure Disk Encryption with BitLocker and DM-Crypt extensions applied to the underlying VM disks.
AnswerC

Azure Key Vault holds customer-managed RSA keys and integrates with Azure SQL Database and Azure Storage through Transparent Data Encryption and storage service encryption with CMK. Granting the resources access via managed identities lets the team disable or rotate the key to revoke access. This satisfies the requirement for internal key control and revocation capability.

Why this answer

Azure Key Vault is the service that stores customer-managed RSA keys and integrates with Azure SQL Database and Azure Storage to encrypt data at rest with keys the organization controls. By granting the PaaS resources access through managed identities, the team can rotate or disable the key to revoke access. Disk Encryption, Information Protection labels, and Confidential Computing address other layers and cannot satisfy the CMK and revocation requirements.

Exam trap

The trap here is confusing encryption-in-use or disk-level encryption features with the key-management service that actually supplies customer-managed keys for Azure PaaS data services.

31
MCQhard

A security administrator is deploying a web application firewall (WAF) to protect a public-facing web application. The application experiences a high volume of traffic from a specific geographic region that is not part of the target customer base. Which WAF feature would best reduce the attack surface without impacting legitimate users?

A.IP whitelisting
B.Rate limiting
C.OWASP rule set
D.Geo-blocking
AnswerD

Geo-blocking filters traffic by source country, dropping requests from the unwanted region at the WAF before they reach the application. Legitimate users elsewhere remain unaffected, reducing the attack surface from that region's hostile traffic without disrupting the target customer base.

Why this answer

Geo-blocking allows the administrator to block traffic from specific regions, reducing the attack surface by eliminating traffic from non-target areas.

32
MCQmedium

A company's compliance team must provide evidence that their cloud environment meets PCI DSS requirements. Which AWS service can aggregate security findings and automate compliance checks?

A.AWS Config
B.AWS Security Hub
C.Amazon Inspector
D.AWS CloudTrail
AnswerB

AWS Security Hub aggregates findings from GuardDuty, Inspector, Macie and Config, then runs automated compliance checks against standards including PCI DSS. This centralised aggregation and automated assessment satisfies the compliance team's evidence requirement, unlike standalone services.

Why this answer

AWS Security Hub aggregates security findings from multiple AWS services and third-party tools, and it can run automated compliance checks against standards like PCI DSS. It provides a central dashboard for security posture. AWS Config records resource configurations but does not aggregate findings or automate compliance checks in the same way.

Amazon Inspector is for vulnerability assessment, and CloudTrail logs API activity.

Exam trap

CV0-004 often tests the confusion between AWS Config (configuration recording) and Security Hub (aggregation and compliance), expecting candidates to know that Security Hub is the aggregator for compliance.

How to eliminate wrong answers

Option A is wrong because AWS Config evaluates resource configurations against desired rules but does not aggregate findings from other services or provide automated compliance checks for standards like PCI DSS. Option C is wrong because Amazon Inspector is a vulnerability management service that scans for software vulnerabilities and network exposures, not a compliance aggregation tool. Option D is wrong because AWS CloudTrail records API calls for auditing but does not aggregate security findings or automate compliance checks.

33
MCQmedium

An organization is subject to PCI DSS compliance and must ensure that all data transmitted between its cloud application and users is encrypted. Which encryption method should be enforced?

A.AES-256
B.TLS 1.2 or higher
C.SHA-256
D.IPsec VPN
AnswerB

TLS 1.2 or higher encrypts data in transit between the cloud application and users, satisfying the PCI DSS requirement for protecting cardholder data over public networks. Earlier protocol versions contain known weaknesses, so enforcing TLS 1.2 as the minimum cipher suite baseline is mandatory.

Why this answer

PCI DSS requires that cardholder data transmitted over open, public networks be protected with strong cryptography. TLS 1.2 or higher is the transport-layer protocol that provides encryption, integrity, and authentication for data in transit between the cloud application and users, satisfying the requirement. AES-256 is the underlying cipher TLS uses, but it is not itself a transmission method.

Exam trap

CV0-004 often tests the confusion between an encryption algorithm (AES-256, SHA-256) and a transport protocol (TLS), so candidates pick the cipher name instead of the protocol that actually secures data in transit.

How to eliminate wrong answers

Option A is wrong because AES-256 is a symmetric block cipher used to encrypt data at rest or as the bulk cipher inside TLS, not a protocol for securing data in transit between a server and users. Option C is wrong because SHA-256 is a cryptographic hash function used for integrity and signatures, not encryption, so it cannot protect confidentiality. Option D is wrong because IPsec VPN encrypts site-to-site or client-to-site tunnels at the network layer, which is not the standard method for securing public web/API traffic to end users and is not what PCI DSS expects for browser-based access.

34
MCQmedium

An organization needs to store database credentials and API keys securely in the cloud, with automatic rotation every 90 days. Which service should be used?

A.AWS CloudHSM
B.AWS Key Management Service (KMS)
C.AWS Systems Manager Parameter Store
D.AWS Secrets Manager
AnswerD

Secrets Manager stores secrets and supports automatic rotation.

Why this answer

AWS Secrets Manager is purpose-built to store database credentials, API keys, and other secrets, and it natively supports automatic rotation on a schedule (for example, every 90 days) using Lambda rotation functions. That combination of secure storage plus managed rotation is exactly what the scenario requires. KMS and Parameter Store do not provide built-in secret rotation for database credentials.

Exam trap

CV0-004 often tests the overlap between KMS, Parameter Store, and Secrets Manager, so candidates pick KMS for 'secure storage' and miss that only Secrets Manager provides native automatic rotation.

How to eliminate wrong answers

Option A is wrong because AWS CloudHSM provides dedicated hardware security modules for key operations and compliance, but it does not store or rotate application secrets like database credentials. Option B is wrong because KMS manages encryption keys and can encrypt secrets, but it has no native secret-rotation feature for credentials. Option C is wrong because Systems Manager Parameter Store can hold SecureString values, but it lacks built-in automatic rotation and lifecycle management for database credentials, so rotation would have to be custom-built.

35
MCQmedium

A cloud administrator notices that an AWS IAM user has more permissions than necessary. Which principle should be applied to correct this?

A.Separation of duties
B.Defense in depth
C.Zero trust
D.Least privilege
AnswerD

Least privilege grants only the permissions required for a user's tasks, directly removing the excessive access the AWS IAM user currently holds. Unlike broader controls such as separation of duties, it targets permission scope itself, satisfying the stem's constraint of more permissions than necessary.

Why this answer

Least privilege means granting an identity only the permissions required to perform its task, and nothing more. When an IAM user has excessive permissions, the correct remediation is to scope the attached policies down to the minimum necessary, which is the definition of least privilege. The other principles address different security concerns and do not directly describe trimming excess permissions.

Exam trap

CV0-004 often tests the distinction between least privilege and zero trust, so candidates pick zero trust because it sounds modern, missing that the question is specifically about trimming excess IAM permissions.

How to eliminate wrong answers

Option A is wrong because separation of duties splits critical functions across different people to prevent fraud, which is about role design rather than reducing an individual's excess permissions. Option B is wrong because defense in depth layers multiple controls (network, host, application) and does not by itself describe removing unnecessary IAM permissions. Option C is wrong because zero trust is an architectural model that verifies every request regardless of network location; it is broader than the specific act of reducing an over-permissioned IAM user.

36
MCQeasy

A cloud administrator is deploying a new containerized workload on Google Kubernetes Engine in Google Cloud. The security team requires that the containers run with a non-root user, have a read-only root filesystem where possible, and are prevented from gaining additional Linux capabilities. Which GKE feature should the administrator enable to enforce these restrictions at the pod level?

A.Pod Security Admission with the restricted profile
B.Shielded GKE Nodes
C.Binary Authorization
D.Network Policy in GKE
AnswerA

Pod Security Admission with the restricted profile enforces hardened pod settings, including running as non-root, disallowing privilege escalation, dropping capabilities, and requiring a seccomp profile. Applying it at the namespace level ensures every pod meets the security team's baseline. It directly maps to the non-root, read-only, and no-new-capabilities requirements.

Why this answer

Pod Security Admission with the restricted profile enforces the exact pod-level controls requested: non-root execution, disallowing privilege escalation, dropping Linux capabilities, and requiring stricter seccomp and filesystem settings. Enabling it on the namespace applies the policy consistently across the workload.

Exam trap

The trap here is selecting a node-hardening or image-provenance feature when the requirement is specifically about runtime pod security context enforcement.

37
Multi-Selectmedium

A cloud administrator is configuring network ACLs (NACLs) for a VPC subnet. The subnet hosts a web server that must accept HTTP (port 80) and HTTPS (port 443) from the internet, and the server needs to respond to clients. Which TWO rules are required?

Select 2 answers
A.Inbound rule: allow all ICMP from 0.0.0.0/0
B.Outbound rule: allow TCP port 80 and 443 to 0.0.0.0/0
C.Inbound rule: allow TCP ports 1024-65535 from 0.0.0.0/0
D.Outbound rule: allow TCP ports 1024-65535 to 0.0.0.0/0
E.Inbound rule: allow TCP port 80 and 443 from 0.0.0.0/0
AnswersD, E

Responses from the web server leave via ephemeral source ports 1024-65535, so the NACL needs an outbound rule permitting that range to 0.0.0.0/0. Without it, return traffic to internet clients is blocked and connections fail.

Why this answer

Option E is correct because the web server must accept inbound HTTP and HTTPS traffic from the internet, so the NACL needs an inbound rule permitting TCP ports 80 and 443 from 0.0.0.0/0. Option D is correct because NACLs are stateless, meaning return traffic is not automatically allowed; the server's responses to clients use ephemeral source ports in the 1024-65535 range, so an outbound rule allowing TCP ports 1024-65535 to 0.0.0.0/0 is required for the responses to reach clients. Option A is not required because ICMP is not needed for HTTP/HTTPS web service and is unrelated to the stated requirement.

Option B is wrong because outbound traffic from the server does not originate from ports 80/443; those are the listening ports, while responses use ephemeral ports. Option C is wrong because inbound client requests target destination ports 80/443, not the ephemeral range, so allowing 1024-65535 inbound would not satisfy the requirement.

Exam trap

CV0-004 often tests the stateless nature of NACLs — candidates incorrectly assume that allowing inbound 80/443 automatically permits return traffic, confusing NACLs with stateful security groups.

38
MCQmedium

A cloud engineer is deploying a containerized application on Kubernetes. The security team requires that containers run with reduced privileges and that certain capabilities are dropped. Which Kubernetes feature should be used to enforce these requirements?

A.Pod Security Standards
B.Network policies
C.ConfigMap
D.Horizontal Pod Autoscaler
AnswerA

Pod Security Standards define the Privileged, Baseline and Restricted profiles, with Restricted enforcing reduced privileges and dropped capabilities such as NET_RAW. Applying these via namespace labels or admission control satisfies the security team's container hardening requirement.

Why this answer

Pod Security Standards (PSS) define three levels (Privileged, Baseline, Restricted) that enforce security controls, including running containers with reduced privileges and dropping capabilities. The Restricted policy specifically requires dropping all capabilities and running as non-root, among other restrictions. Therefore, PSS is the correct feature to enforce these requirements.

Exam trap

The trap is confusing Pod Security Standards with other Kubernetes features like Network Policies or RBAC; candidates might think Network Policies control container privileges, but they only control network traffic.

How to eliminate wrong answers

Option B is wrong because Network policies control network traffic between pods, not container privileges or capabilities. Option C is wrong because ConfigMaps are used to store configuration data, not to enforce security policies. Option D is wrong because Horizontal Pod Autoscaler automatically scales the number of pods based on metrics, not security settings.

39
MCQmedium

A security team needs to enforce multi-factor authentication (MFA) for all users accessing the cloud management console. Which IAM feature should be configured?

A.IAM role
B.Condition in IAM policy requiring MFA
C.Resource-based policy
D.Password policy
AnswerB

An IAM policy condition evaluating the MFA claim denies console access unless the principal authenticated with a second factor, satisfying the requirement to enforce MFA for all management-console users. The condition is evaluated at request time, so unauthenticated sessions are blocked before any action is permitted.

Why this answer

A condition in an identity policy can require the presence of multi-factor authentication, enforcing MFA for access to the cloud management console. This is a standard mechanism to mandate MFA at the policy level, ensuring users must authenticate with a second factor before accessing the console.

Exam trap

A common misconception is that password policies can enforce MFA, but password policies only control password attributes, not the second authentication factor required by MFA.

How to eliminate wrong answers

Option A is wrong because an IAM role is used to delegate permissions to entities (like EC2 instances or federated users) and does not inherently enforce MFA; it can be assumed without MFA unless a condition is added. Option C is wrong because a resource-based policy (e.g., an S3 bucket policy) controls access to specific resources, not the cloud management console itself, and cannot enforce MFA for console login. Option D is wrong because a password policy only governs password complexity and rotation rules, not multi-factor authentication; MFA enforcement requires a separate IAM policy condition.

40
MCQhard

A company's cloud environment uses Azure Active Directory for identity management. They want to allow employees to sign in using their existing on-premises Active Directory credentials without synchronizing passwords to the cloud. Which federation protocol should they use?

A.LDAP
B.Kerberos
C.OAuth 2.0
D.SAML 2.0
AnswerD

SAML 2.0 federates identity so Microsoft Entra ID trusts authentication assertions from on-premises Active Directory, letting employees sign in with existing credentials. This satisfies the stem's no-password-synchronisation constraint, unlike password hash synchronisation, which replicates credentials to the cloud.

Why this answer

SAML 2.0 is the correct choice because it is a federation protocol designed for web-based single sign-on (SSO), allowing Azure AD to trust authentication assertions issued by on-premises Active Directory Federation Services (AD FS) without replicating password hashes to the cloud. Azure AD supports SAML 2.0 as a federated identity provider, so users authenticate on-premises and receive a signed token that Azure AD accepts. This satisfies the requirement of using existing AD credentials without password synchronization.

Exam trap

CV0-004 often tests the confusion between authentication protocols (Kerberos, LDAP) and federation protocols (SAML, WS-Federation, OpenID Connect), tricking candidates into picking Kerberos because it is the native AD protocol.

How to eliminate wrong answers

Option A is wrong because LDAP is a directory access protocol used for querying and modifying directory data, not for federated web SSO between identity providers. Option B is wrong because Kerberos is a ticket-based authentication protocol used within a domain (or with cross-realm trusts), not a federation protocol for cloud SSO with Azure AD. Option C is wrong because OAuth 2.0 is an authorization framework for delegated access to APIs, not an authentication/federation protocol for signing users into Azure AD with on-premises credentials.

41
MCQmedium

A cloud administrator needs to ensure that a set of AWS EC2 instances can only be accessed via SSH from the corporate office IP range 203.0.113.0/24. Which configuration should the administrator implement?

A.Create a security group with an inbound rule allowing TCP port 22 from 203.0.113.0/24
B.Deploy a VPN and require all SSH traffic to go through it
C.Configure a network ACL with an inbound allow rule for TCP port 22 from 203.0.113.0/24
D.Use AWS WAF to block SSH traffic except from 203.0.113.0/24
AnswerA

Security groups are stateful, instance-level virtual firewalls whose inbound rules filter by protocol, port and source CIDR. Allowing TCP 22 solely from 203.0.113.0/24 restricts SSH to the corporate range, satisfying the stated access constraint without affecting other traffic.

Why this answer

A security group acts as a stateful virtual firewall for EC2 instances. By specifying the source IP range 203.0.113.0/24 on the inbound SSH rule, only traffic from that range is allowed. Security groups are stateful, so return traffic is automatically permitted.

42
MCQhard

A financial services company runs a multi-tenant SaaS application on AWS. Each tenant has dedicated Amazon RDS for MySQL databases. The security team must ensure that data at rest is encrypted with keys that are unique per tenant and that the company can independently audit key usage. Which approach should be used?

A.Use a single customer managed key (CMK) in AWS KMS for all RDS instances
B.Use client-side encryption with a per-tenant key stored in the application
C.Use a separate customer managed key (CMK) in AWS KMS for each tenant's RDS instance
D.Use AWS managed keys (aws/rds) for each RDS instance
AnswerC

Creating a unique CMK per tenant in AWS KMS allows each RDS instance to be encrypted with its own key. The company can audit key usage separately through CloudTrail, meeting the audit requirement. This provides strong isolation: compromise of one key does not affect other tenants. It also enables per-tenant key rotation and access policies.

Why this answer

Using a separate AWS KMS customer managed key for each tenant's RDS instance provides unique encryption keys per tenant, enabling strong isolation and independent auditability. CloudTrail logs each key's usage, so the security team can track which key encrypted which database and when. This meets both the security and compliance requirements without application-level complexity.

Exam trap

The trap here is assuming that a single CMK or AWS managed keys provide sufficient isolation, when the requirement explicitly demands unique keys per tenant and independent auditing.

43
MCQmedium

A cloud operations team manages a multi-account AWS environment. Auditors require that every API call made in all accounts be logged to a central location, that logs be immutable for 90 days, and that the logs capture the identity of the caller, the source IP, and the request time. The team wants minimal custom development. Which combination should the team implement?

A.Amazon CloudWatch Logs with subscription filters forwarding application logs to a central account.
B.AWS Config recording all resource configurations in each account and aggregating them into a central aggregator account.
C.AWS CloudTrail organization trail delivering to a central S3 bucket with S3 Object Lock in compliance mode and a bucket policy denying deletes.
D.AWS Security Hub aggregating findings from GuardDuty and Inspector into a central administrator account.
AnswerC

An organization trail in CloudTrail automatically logs management events from all accounts in AWS Organizations to a single S3 bucket. CloudTrail records caller identity, source IP, and event time. S3 Object Lock in compliance mode with a deny-delete bucket policy makes the logs immutable for the retention period. This meets all requirements with minimal custom code.

Why this answer

A CloudTrail organization trail is the AWS-native way to capture API activity across all accounts in AWS Organizations into one central S3 bucket. CloudTrail events include caller identity, source IP, and event time. Applying S3 Object Lock in compliance mode plus a bucket policy that denies deletion provides the required 90-day immutability.

The other services handle configuration, application logs, or findings, none of which produce the required centralized, immutable API audit trail.

Exam trap

The trap here is selecting a monitoring or configuration service such as AWS Config, CloudWatch, or Security Hub when the requirement is specifically an immutable record of every API call with caller identity and source IP.

44
MCQmedium

A cloud administrator manages a Microsoft Azure subscription. The security team requires that all virtual machines in a resource group be protected by a host-based firewall that filters traffic by port and protocol, independent of any network security group rules. The administrator needs a solution that can be applied directly to the operating system of each VM. Which solution should the administrator implement?

A.Enable Azure DDoS Protection Standard on the virtual network.
B.Configure Azure Firewall in the virtual network.
C.Apply a network security group (NSG) to each VM's network interface.
D.Install and configure a host-based firewall such as Windows Defender Firewall or iptables on each VM.
AnswerD

A host-based firewall runs inside the guest operating system and filters traffic by port, protocol, and application, independent of Azure network controls. Windows Defender Firewall and iptables are examples that satisfy the requirement to protect each VM directly at the OS level. This approach provides the granular, per-VM filtering the security team requested.

Why this answer

The requirement is for a host-based firewall that filters traffic by port and protocol directly on each VM's operating system. Only a firewall installed inside the guest OS, such as Windows Defender Firewall or iptables, meets this need. Azure-native services like Firewall, NSGs, and DDoS Protection operate at the network layer and cannot enforce OS-level filtering.

Exam trap

The trap here is assuming that Azure network security controls such as NSGs or Azure Firewall provide host-based protection, when they actually operate at the network layer and cannot filter traffic inside the VM operating system.

45
MCQmedium

A cloud administrator manages an AWS environment where developers require temporary, least-privilege access to specific S3 buckets. The administrator wants to avoid creating long-term IAM user credentials and needs the ability to audit who assumed which role and when. Which AWS service should be used to issue short-lived credentials for these developers?

A.AWS Security Token Service (STS)
B.AWS Key Management Service (KMS) data keys
C.AWS Organizations service control policies (SCPs)
D.AWS Identity and Access Management (IAM) access keys
AnswerA

AWS STS issues temporary, limited-privilege credentials that expire after a defined duration. By calling AssumeRole, developers receive short-lived credentials tied to an IAM role, and AWS CloudTrail logs the AssumeRole event for auditing. This directly satisfies the need for temporary access without long-term IAM user credentials and provides the required audit trail.

Why this answer

The requirement is for temporary credentials that expire automatically and can be audited. AWS STS provides exactly that through mechanisms like AssumeRole, which returns short-lived credentials associated with an IAM role. CloudTrail records the AssumeRole call, giving the administrator visibility into who assumed which role and when.

Other options either provide long-term credentials or do not issue credentials at all.

Exam trap

The trap here is confusing IAM access keys with temporary credentials, assuming that any IAM-issued key is short-lived when in fact access keys are long-term unless explicitly rotated.

46
MCQmedium

A company has a requirement to enforce least privilege for its cloud resources. The cloud engineer is configuring IAM policies. Which of the following best describes least privilege?

A.Granting permissions based on the user's job title rather than specific needs
B.Granting permissions only to senior managers
C.Granting only the permissions necessary to perform specific tasks
D.Granting full administrator access to all users to simplify management
AnswerC

Granting only the permissions necessary to perform specific tasks directly satisfies the least-privilege requirement by scoping each identity to the minimum actions its role demands. Unlike broad or standing access, this limits the blast radius of compromised credentials, aligning with Microsoft Entra ID role assignments and just-in-time access patterns that enforce task-specific authorisation.

Why this answer

Least privilege means granting each user or service only the minimum permissions required to perform their specific job functions, and nothing more. This limits the blast radius of compromised credentials and reduces accidental or malicious damage. In cloud IAM, this is implemented through fine-grained policies scoped to specific resources and actions.

Exam trap

CV0-004 often tests the difference between least privilege and role-based access control, and candidates incorrectly pick job-title-based granting thinking it satisfies least privilege when it does not.

How to eliminate wrong answers

Option A is wrong because granting permissions based on job title rather than actual tasks is role-based but not least-privilege — job titles often imply broader access than needed, and two people with the same title may need different permissions. Option B is wrong because restricting permissions to senior managers is not least privilege; it is a hierarchical access model that ignores actual task requirements and may over-privilege managers while under-privileging others. Option D is wrong because granting full administrator access to everyone is the opposite of least privilege and dramatically increases risk.

47
MCQmedium

A cloud administrator is configuring a Linux virtual machine in Google Cloud. The security policy requires that all administrative access to the VM use short-lived SSH certificates issued by an internal certificate authority, rather than static SSH keys. Which GCP feature should be used to meet this requirement?

A.OS Login with SSH certificate authority
B.OS Login with two-factor authentication
C.Google Cloud IAP TCP forwarding with SSH
D.IAM roles with SSH key metadata
AnswerA

OS Login can be configured to use an SSH certificate authority. When enabled, the organization's CA issues short-lived SSH certificates to users, and OS Login validates them against the CA's public key. This eliminates static SSH keys and meets the requirement for short-lived, certificate-based administrative access to the Linux VM in Google Cloud.

Why this answer

OS Login with an SSH certificate authority allows the organization to issue short-lived SSH certificates from an internal CA. Users authenticate with these certificates, and OS Login validates them, removing the need for static SSH keys. This directly fulfills the security policy requiring short-lived certificate-based administrative access.

Exam trap

The trap here is assuming that OS Login or IAP alone provides certificate-based authentication, when only the SSH certificate authority integration issues short-lived certificates.

48
Multi-Selecteasy

A company is adopting a shared responsibility model for a PaaS cloud deployment. Which THREE responsibilities belong to the customer?

Select 3 answers
A.Management of the runtime environment
B.Physical security of data centers
C.Data classification and encryption
D.Application code security
E.User access and identity management
AnswersC, D, E

The customer decides how to classify and encrypt data.

Why this answer

In a PaaS shared responsibility model, the customer is responsible for data classification and encryption of data at rest and in transit. The cloud provider manages the underlying infrastructure, but the customer must classify data according to sensitivity and apply encryption mechanisms, such as using TLS 1.2/1.3 for data in transit and AES-256 for data at rest, as the provider cannot access or classify customer data.

Exam trap

The CV0-004 exam often tests the misconception that the customer manages the runtime environment in PaaS, but the trap here is that PaaS abstracts the runtime, so the provider handles it, while the customer's responsibilities are limited to data, application code, and access control.

49
Multi-Selectmedium

A cloud architect is designing a container security strategy. Which TWO of the following should be implemented to secure containers? (Choose two.)

Select 2 answers
A.Runtime security monitoring for anomalous behavior
B.Disabling all security contexts in Kubernetes
C.Image scanning for vulnerabilities
D.Using the latest base images without scanning
E.Implementing network ACLs at the hypervisor level
AnswersA, C

Runtime security monitoring detects anomalous behaviour in running containers, such as unexpected process execution or privilege escalation, which static image scanning cannot catch. It satisfies the requirement to secure containers throughout their lifecycle, not only at build time.

Why this answer

Option A (Runtime security monitoring for anomalous behavior) is correct because containers can be compromised after deployment, and runtime monitoring detects suspicious activity such as unexpected process execution, privilege escalation, or unauthorized file access, enabling rapid response to threats that static controls miss. Option C (Image scanning for vulnerabilities) is correct because container images often include outdated OS packages and libraries with known CVEs; scanning images in the CI/CD pipeline and registry before deployment prevents vulnerable artifacts from reaching production. Option B is wrong because disabling all security contexts removes controls like runAsNonRoot, readOnlyRootFilesystem, and dropped capabilities, weakening rather than strengthening container isolation.

Option D is wrong because using the latest base images without scanning provides no assurance that known vulnerabilities are absent and can introduce unreviewed changes. Option E is wrong because network ACLs at the hypervisor level do not address container-specific risks such as image vulnerabilities or runtime compromise, and container network policy is typically enforced via Kubernetes NetworkPolicy or service mesh rather than hypervisor ACLs.

Exam trap

CV0-004 often tests the misconception that hypervisor-level network ACLs secure containers, but containers require orchestration-aware policies like Kubernetes NetworkPolicies; also, candidates may think disabling security contexts simplifies management, but it removes essential isolation.

50
MCQmedium

A company stores sensitive customer data in an S3 bucket and must encrypt the data at rest using a key managed by the company (not AWS). Which encryption option should the company use?

A.Client-side encryption
B.SSE-C
C.SSE-KMS
D.SSE-S3
AnswerB

SSE-C lets the company supply and retain its own encryption key, which AWS never stores, satisfying the requirement for customer-managed keys. SSE-S3 and SSE-KMS use AWS-managed or AWS-held key material, so neither meets the constraint of company-managed keys.

Why this answer

SSE-C (Server-Side Encryption with Customer-Provided Keys) allows the company to provide their own encryption key with each request, and AWS uses that key to encrypt the object at rest but does not store the key. This meets the requirement that the key is managed by the company, not AWS.

Exam trap

The trap here is confusing SSE-KMS with customer-managed keys: candidates may think 'customer managed key' in KMS means the company manages the key, but the question explicitly says 'not AWS', and SSE-KMS still involves AWS KMS managing the key material, whereas SSE-C requires the customer to provide the key.

How to eliminate wrong answers

Option A is wrong because client-side encryption means the company encrypts data before uploading, but the question specifies encryption at rest in S3 and a key managed by the company; client-side encryption is a valid approach but SSE-C is the specific S3 server-side option where the customer manages the key. Option C is wrong because SSE-KMS uses AWS KMS-managed keys (though customer master keys can be customer-managed, the key material is still managed by AWS KMS, and the question says 'not AWS'). Option D is wrong because SSE-S3 uses AWS-managed keys entirely, so the company does not manage the key.

51
Multi-Selecthard

A company is implementing a secrets management solution. The security team wants to ensure that secrets are protected and rotated regularly. Which THREE of the following are best practices for secrets management?

Select 3 answers
A.Audit access to secrets to detect unauthorized usage.
B.Hard-code secrets in application source code for simplicity.
C.Use a dedicated secrets management service like AWS Secrets Manager or Azure Key Vault.
D.Enable automatic rotation of secrets on a regular schedule.
E.Store secrets in environment variables for easy access by applications.
AnswersA, C, D

Auditing secret access produces an immutable record of who read or modified each credential, exposing misuse, stale integrations or compromised identities. It satisfies the stem's protection goal by enabling detection of unauthorised usage before rotation alone would reveal it.

Why this answer

Best practices include using a dedicated vault, rotating secrets, avoiding hard-coded secrets, and auditing access.

52
MCQhard

A company uses AWS and needs to enforce that all S3 buckets are encrypted at rest with customer-managed keys stored in AWS KMS. Which IAM policy condition would ensure this?

A.s3:x-amz-server-side-encryption-aws-kms-key-id
B.s3:x-amz-server-side-encryption with value AES256
C.aws:SourceVpce
D.s3:versioning
AnswerA

This condition allows requiring a specific KMS key ARN for encryption.

Why this answer

The 'aws:RequestTag' condition (or similar) can enforce that resources are created with specific tags, but to enforce encryption key usage, the condition 's3:x-amz-server-side-encryption-aws-kms-key-id' is used.

53
MCQeasy

An administrator is configuring access to a cloud management console for a large team. The organization wants to require a second authentication factor for all users and centralize the identity source so that disabling an account in the corporate directory immediately removes cloud access. Which approach should the administrator implement?

A.Federate the cloud provider with the corporate directory using SAML or OIDC and enforce multi-factor authentication at the identity provider.
B.Issue each user a long-lived cloud API access key and require them to use it when signing in to the management console.
C.Share a single privileged cloud account among the team and rotate its password on a weekly schedule.
D.Create separate local cloud accounts for each user and enforce a strong password complexity policy on each one.
AnswerA

Federation makes the corporate directory the single source of truth, so disabling an account there immediately blocks cloud sign-in because the identity provider no longer issues assertions. Enforcing multi-factor authentication at the identity provider applies the second factor uniformly across every federated application, satisfying both requirements without duplicating identities in the cloud.

Why this answer

Identity federation with the corporate directory through SAML or OIDC establishes one authoritative identity source, so deactivating a directory account instantly prevents new cloud sessions. Enforcing multi-factor authentication at the identity provider applies the second factor consistently to every federated sign-in, meeting both the centralization and the stronger-authentication goals without maintaining duplicate cloud identities.

Exam trap

The trap here is believing that strong local passwords provide the same control as directory-backed federation with enforced multi-factor authentication.

54
MCQhard

A financial services firm stores regulated customer records in an object storage bucket in a public cloud. A compliance auditor requires that every object be encrypted with a customer-managed key so the firm can revoke access instantly and prove key custody, while still allowing the provider to perform envelope encryption for performance. Which configuration meets these requirements?

A.Enable provider-managed default encryption on the bucket using keys the cloud provider generates and rotates automatically.
B.Configure the bucket to use a customer-managed key stored in the cloud key management service, with automatic key rotation and an audit trail of key usage.
C.Encrypt each object client-side with an application-held symmetric key before uploading, and store the ciphertext in the bucket.
D.Apply a bucket policy that denies unencrypted uploads and rely on transport layer security to protect objects at rest.
AnswerB

Customer-managed keys in the provider's key management service keep custody with the organization, allow immediate revocation by disabling or deleting the key, and produce an auditable usage trail. The provider still performs envelope encryption, generating a data key per object that is wrapped by the customer-managed key, so performance and server-side functionality are preserved while compliance evidence is generated.

Why this answer

Customer-managed keys held in the cloud key management service satisfy custody and revocation requirements because the organization controls the key lifecycle and can disable the key to cut off decryption instantly. The provider still performs envelope encryption by generating per-object data keys wrapped by the customer-managed key, which keeps performance high and maintains an auditable record of every cryptographic operation.

Exam trap

The trap here is conflating encryption at rest with key custody, since provider-managed default encryption encrypts data but leaves the organization unable to revoke access.

55
MCQeasy

An organization is moving sensitive data to the cloud and must ensure it is encrypted while stored on disk. Which type of encryption should be implemented?

A.Encryption in transit
B.Encryption at rest
C.Hashing
D.Tokenization
AnswerB

Encryption at rest protects data written to persistent storage, such as cloud disks and object stores, by encrypting it before it is saved. This directly satisfies the requirement that sensitive data remain encrypted while stored on disk.

Why this answer

Encryption at rest protects data stored on disk, typically using AES-256.

56
MCQmedium

A company is migrating to a public cloud and wants to understand security responsibilities. According to the shared responsibility model, which of the following is the customer responsible for in an IaaS deployment?

A.Patching the guest operating system
B.Network infrastructure security
C.Physical security of data centers
D.Hypervisor security
AnswerA

In IaaS the provider secures the physical hosts, network and hypervisor, while the customer retains control of everything from the guest operating system upward. Patching the guest OS therefore remains the customer's responsibility, unlike PaaS or SaaS where the provider handles it.

Why this answer

In an IaaS deployment, the customer is responsible for patching the guest operating system (A). Under the shared responsibility model, the cloud provider manages the physical security, network infrastructure, and hypervisor, while the customer is responsible for the security of everything they deploy on the infrastructure, including the guest OS, applications, and data. Patching the guest OS is a customer task because the customer has control over the OS and its configuration.

Exam trap

The trap is confusing the responsibilities of the cloud provider and customer, often assuming the provider handles more than they do, such as OS patching in IaaS.

How to eliminate wrong answers

Option B is wrong because network infrastructure security (e.g., routers, switches, physical network) is managed by the cloud provider in IaaS. Option C is wrong because physical security of data centers is always the responsibility of the cloud provider. Option D is wrong because hypervisor security is managed by the cloud provider, as the hypervisor is part of the virtualization infrastructure.

57
MCQhard

A company running a critical web application wants to protect against SQL injection and cross-site scripting attacks. The application is behind a load balancer. Which type of service should be deployed to provide this protection?

A.Network firewall
B.DDoS protection service
C.Intrusion detection system
D.Web application firewall (WAF)
AnswerD

A WAF inspects HTTP/HTTPS traffic at layer 7, matching signatures to block SQL injection and cross-site scripting payloads before they reach the application. Deployed behind the load balancer, it satisfies the requirement to filter malicious web requests targeting this critical application.

Why this answer

A web application firewall (WAF) is designed to protect web applications from common web exploits like SQL injection and cross-site scripting. It can be integrated with load balancers to inspect HTTP/HTTPS traffic and filter malicious requests based on customizable rules. This makes it the correct choice for the described threat scenario.

Exam trap

The trap here is that candidates often confuse a web application firewall with a DDoS protection service, thinking the latter provides application-layer attack protection. However, DDoS protection focuses on volumetric attacks while a WAF handles web-specific exploits like SQL injection and XSS.

How to eliminate wrong answers

Option A is wrong because AWS Network Firewall is a stateful managed firewall for VPC network traffic, operating at layers 3-4 and 7 for network protocols, but it does not provide application-layer inspection for SQL injection or XSS payloads in HTTP requests. Option B is wrong because AWS Shield Advanced provides DDoS protection against volumetric and state-exhaustion attacks, not against application-layer threats like SQL injection or XSS. Option C is wrong because AWS GuardDuty is a threat detection service that analyzes VPC flow logs, DNS logs, and CloudTrail events for malicious activity, but it does not actively block or filter web application attacks like SQL injection or XSS.

58
MCQmedium

A company uses a SaaS application for customer relationship management (CRM). The security team wants to monitor user activities and enforce data loss prevention (DLP) policies. Which type of security tool should be deployed?

A.Intrusion Detection System (IDS)
B.Security Information and Event Management (SIEM)
C.Cloud Access Security Broker (CASB)
D.Web Application Firewall (WAF)
AnswerC

A CASB sits between users and the SaaS CRM, providing activity monitoring and enforcing DLP policies on cloud traffic. It satisfies the stem's constraint of governing a SaaS application, which endpoint or network tools cannot inspect directly.

Why this answer

A Cloud Access Security Broker (CASB) provides visibility into SaaS usage, monitors user activities, and can enforce DLP policies across cloud applications.

59
Multi-Selectmedium

A cloud operations team is hardening a Microsoft Azure subscription that hosts production virtual machines. The security lead wants to ensure that only approved operating system images can be deployed and that any drift from the baseline configuration is automatically detected. Which TWO Azure services should be implemented to meet these goals? (Choose two.)

Select 2 answers
A.Azure Policy with a custom definition restricting allowed image publishers and offers
B.Azure Policy with the built-in 'Allowed virtual machine size SKUs' initiative
C.Azure Automation State Configuration (DSC)
D.Azure Advisor security recommendations
E.Microsoft Defender for Cloud regulatory compliance dashboard
AnswersA, C

Azure Policy can enforce that VMs may only be created from approved image publishers, offers, and SKUs by evaluating the imageReference property. This directly prevents deployment of unapproved operating system images. Combined with a drift-detection service, it fulfills the requirement to restrict images to an approved set.

Why this answer

Azure Policy with a custom image restriction definition enforces that only approved OS images can be deployed, directly satisfying the image control requirement. Azure Automation State Configuration continuously evaluates VMs against a DSC baseline and reports drift, satisfying the drift detection requirement. Together they provide both preventive and detective controls for the production subscription.

Exam trap

The trap here is selecting broad posture or advisory tools like Defender for Cloud or Advisor, which report on compliance but do not enforce image approval or continuously detect configuration drift.

60
Multi-Selecthard

A company is migrating to AWS and needs to meet PCI DSS compliance. Which THREE of the following should be implemented? (Choose three.)

Select 3 answers
A.Encrypting cardholder data at rest and in transit
B.Using single-factor authentication for all administrative access
C.Implementing a vulnerability management program
D.Enabling audit logging for all access to cardholder data
E.Using default VPC settings without changes
AnswersA, C, D

Encrypting cardholder data at rest and in transit directly satisfies PCI DSS Requirement 4, which mandates strong cryptography for cardholder data during transmission over open, public networks and while stored. This controls the core constraint of protecting sensitive authentication data throughout its lifecycle, a mandatory baseline for any PCI DSS compliant AWS migration.

Why this answer

PCI DSS requires encryption of cardholder data, regular security testing (like vulnerability scanning), and audit logging. Using default VPC settings may not be secure. Single-factor authentication is insufficient.

61
MCQmedium

A security analyst is reviewing logs and finds that an unauthorized user accessed a storage blob in a cloud environment. The analyst needs to determine which permissions allowed the access. Which cloud feature provides a detailed view of effective permissions for a user?

A.Privileged Identity Management (PIM)
B.Role-Based Access Control (RBAC) with effective permissions analysis
C.Blueprints/Service Catalog
D.Policy Enforcement
AnswerB

RBAC with effective permissions analysis aggregates every role assignment, including inherited and group-derived ones, into a single evaluated view, revealing exactly which permission granted the blob access. This directly satisfies the analyst's need to trace the specific authorisation path rather than inspecting raw role definitions individually.

Why this answer

Role-Based Access Control (RBAC) systems often provide an 'effective permissions' or 'check access' feature that allows an administrator to evaluate the cumulative permissions assigned to a specific user, group, or service principal for a given resource scope. This feature calculates the net effect of all role assignments, including inherited permissions from higher-level scopes such as management groups, subscriptions, and resource groups, enabling the analyst to pinpoint exactly which role granted the unauthorized access.

Exam trap

The trap here is that candidates often confuse RBAC's effective permissions feature with Privileged Identity Management (PIM), assuming PIM shows current permissions, when in fact PIM only manages role activation and does not compute the cumulative effective permissions across multiple role assignments.

How to eliminate wrong answers

Option A is wrong because Azure AD Privileged Identity Management (PIM) manages just-in-time activation and oversight of privileged roles, but it does not provide a detailed view of effective permissions for a specific user on a resource. Option C is wrong because Azure Blueprints is used for defining and deploying repeatable sets of Azure resources and policies (like compliance templates), not for evaluating effective user permissions. Option D is wrong because Azure Policy enforces rules and effects (e.g., deny, audit) on resource configurations, but it does not evaluate or display the effective RBAC permissions assigned to a user.

62
MCQhard

A cloud security team is implementing a secrets management solution for applications running on AWS. They need to automatically rotate database credentials every 30 days and avoid hardcoding secrets. Which service should they use?

A.AWS Identity and Access Management (IAM) roles
B.AWS Key Management Service (KMS)
C.AWS Secrets Manager
D.AWS Systems Manager Parameter Store
AnswerC

AWS Secrets Manager natively performs scheduled rotation of database credentials via Lambda rotation functions, satisfying the 30-day rotation requirement, and applications retrieve secrets through API calls at runtime rather than embedding them in code, eliminating hardcoded credentials.

Why this answer

AWS Secrets Manager allows automatic rotation of secrets (e.g., database credentials) and integration with AWS services. Parameter Store can store secrets but does not natively support automatic rotation. KMS is for encryption keys.

IAM roles are for AWS service permissions.

63
MCQmedium

An organization uses multiple SaaS applications and wants to enforce data loss prevention policies and gain visibility into user activity. Which technology should they implement?

A.Security information and event management (SIEM)
B.Web Application Firewall (WAF)
C.Virtual private network (VPN)
D.Cloud Access Security Broker (CASB)
AnswerD

A CASB sits between users and SaaS providers, giving visibility into sanctioned and unsanctioned application usage while enforcing data loss prevention policies inline. That API and proxy-based inspection satisfies both the visibility and DLP requirements across multiple SaaS applications.

Why this answer

A Cloud Access Security Broker (CASB) sits between users and SaaS applications to enforce DLP policies, provide visibility into shadow IT, and monitor user activity across multiple cloud services. CASB is specifically designed for the SaaS visibility and control use case described, offering API-based and proxy-based modes. It can inspect data in transit and at rest in sanctioned SaaS apps, apply DLP rules, and generate audit trails.

Exam trap

CV0-004 often tests the distinction between CASB and SIEM — candidates confuse visibility (SIEM) with policy enforcement and control over SaaS (CASB), picking SIEM when the requirement includes DLP enforcement.

How to eliminate wrong answers

Option A is wrong because SIEM aggregates and correlates log data for security monitoring and incident response, but it does not enforce DLP policies or provide inline control over SaaS user activity — it is a detection and analysis tool, not a policy enforcement point. Option B is wrong because a WAF protects web applications from HTTP-layer attacks (SQLi, XSS) and does not govern SaaS usage or data flows to third-party cloud apps. Option C is wrong because a VPN provides encrypted remote access to a corporate network but does not inspect or control SaaS application usage or enforce DLP.

64
Multi-Selectmedium

A cloud security team is hardening a Microsoft Azure subscription that hosts production virtual machines. The team must ensure that administrative access to the VMs requires multi-factor authentication and that privileged role assignments are reviewed on a recurring basis. (Choose two.)

Select 2 answers
A.Enable Microsoft Entra multifactor authentication and enforce it through a Conditional Access policy scoped to the Azure portal and VM management.
B.Assign the Owner role at the subscription scope to all administrators so they can manage access reviews themselves.
C.Configure Microsoft Entra Privileged Identity Management access reviews for privileged Azure resource roles on a recurring schedule.
D.Create a custom Azure Policy that audits virtual machines lacking the latest OS patches.
E.Enable just-in-time VM access in Microsoft Defender for Cloud and rely on it as the sole authentication control.
AnswersA, C

Conditional Access is the policy engine that evaluates signals such as user, device, and location, then enforces controls like multifactor authentication. Scoping the policy to the Azure portal and VM management ensures administrators must satisfy MFA before reaching privileged VM operations. This directly satisfies the requirement that administrative access require MFA.

Why this answer

The two requirements are MFA for administrative access and recurring review of privileged role assignments. Conditional Access enforces MFA for the portal and VM management paths, while Privileged Identity Management access reviews provide scheduled attestation of privileged roles and can revoke access automatically. The other choices either weaken privilege boundaries, address network reachability, or focus on patching rather than identity controls.

Exam trap

The trap here is conflating network-level controls like just-in-time VM access with identity-level MFA enforcement, when only Conditional Access actually requires a second authentication factor.

65
MCQmedium

A company is using a SaaS application and wants to gain visibility into user activity and enforce data loss prevention policies. Which technology should be deployed?

A.Intrusion Detection System (IDS)
B.Web Application Firewall (WAF)
C.Cloud Access Security Broker (CASB)
D.Network Access Control (NAC)
AnswerC

A CASB sits between users and the SaaS provider, providing API and proxy-based visibility into user activity plus inline DLP enforcement. It satisfies the stem's SaaS visibility and policy requirement, unlike SWG or firewall approaches that cannot inspect sanctioned SaaS traffic.

Why this answer

A Cloud Access Security Broker (CASB) is a security policy enforcement point placed between cloud service consumers and cloud service providers to combine and interject enterprise security policies as cloud-based resources are accessed. It provides visibility into user activity, enforces data loss prevention (DLP) policies, and ensures compliance for SaaS applications.

Exam trap

CV0-004 often tests the confusion between network security tools (IDS, WAF, NAC) and cloud-specific security controls (CASB), so candidates must recognize that only CASB provides SaaS visibility and DLP.

How to eliminate wrong answers

Option A is wrong because an Intrusion Detection System (IDS) monitors network traffic for malicious activity but does not provide granular visibility into SaaS user activity or enforce DLP policies. Option B is wrong because a Web Application Firewall (WAF) protects web applications from attacks like SQL injection and XSS, but it does not govern SaaS usage or data loss. Option D is wrong because Network Access Control (NAC) controls device access to the network based on compliance, not SaaS application activity or DLP.

66
Multi-Selectmedium

A cloud security engineer is hardening a Kubernetes cluster. Which TWO measures should be implemented to improve container security? (Choose two.)

Select 2 answers
A.Implement runtime security monitoring
B.Store secrets in ConfigMaps
C.Disable audit logging to reduce overhead
D.Use default service accounts for all pods
E.Enable image scanning for vulnerabilities
AnswersA, E

Runtime security detects suspicious container behavior.

Why this answer

A is correct because runtime security monitoring (e.g., using Falco, Sysdig, or Aqua Security) detects and alerts on anomalous behavior within running containers, such as unexpected system calls, privilege escalations, or file system changes. This is a critical layer of defense that complements image scanning by catching threats that bypass static checks, such as zero-day exploits or compromised containers. Without runtime monitoring, malicious activity inside a container can go undetected until significant damage occurs.

Exam trap

A common misconception is that ConfigMaps are a secure place for secrets, but ConfigMaps lack encryption and access control features, making them unsuitable for sensitive data.

67
MCQmedium

A security team discovers that a container image used in production contains a known vulnerability in one of its base image layers. Which action should be taken to remediate this issue?

A.Rebuild the container image using an updated base image
B.Delete the container and recreate it from the same image
C.Apply a security patch to the running container
D.Enable runtime security monitoring to detect exploitation attempts
AnswerA

Rebuilding with an updated base image replaces the vulnerable layer, removing the inherited flaw while preserving application code. Patching the running container alone would not remediate the image itself, so rebuilding is the correct action.

Why this answer

When a vulnerability is found in a base image layer, the correct remediation is to rebuild the container image using an updated base image that includes the patched version of the affected component. Containers are immutable, so patching a running container does not persist and does not fix the image. Rebuilding ensures the new image is free of the vulnerability and can be redeployed across the environment.

Exam trap

CV0-004 often tests the misconception that you can patch a running container to fix a vulnerability, when containers are immutable and the fix must be applied to the image and redeployed.

How to eliminate wrong answers

Option B is wrong because deleting and recreating a container from the same image reproduces the same vulnerable layer, so the vulnerability remains. Option C is wrong because applying a patch to a running container is a temporary, non-persistent change that is lost on restart and does not fix the underlying image used for future deployments. Option D is wrong because runtime security monitoring only detects exploitation attempts; it does not remediate the vulnerability itself and leaves the production environment exposed.

68
MCQmedium

A cloud security team is implementing a key management strategy for workloads spread across AWS and Azure. The team wants a single system of record for cryptographic keys, with the ability to import existing keys from on-premises HSMs, enforce automatic annual rotation, and produce immutable audit logs of every key use. Which approach best satisfies these requirements?

A.Deploy a dedicated FIPS 140-2 Level 3 HSM cluster in each cloud region and use the provider's native key management to front the cluster.
B.Use AWS KMS with a multi-Region customer managed key and replicate key metadata to Azure Key Vault.
C.Store all keys in an encrypted S3 bucket with Object Lock and grant both clouds access through cross-account IAM roles.
D.Implement a centralized external key manager with cloud-native integrations, using BYOK import, policy-driven rotation, and tamper-evident logging.
AnswerD

A centralized external key manager integrated with both AWS KMS and Azure Key Vault provides one authoritative system of record. It supports BYOK import from on-premises HSMs, enforces rotation policies centrally, and emits tamper-evident audit logs for every cryptographic operation. This directly satisfies the single-source, import, rotation, and immutable-audit requirements across the multi-cloud environment.

Why this answer

Centralizing key custody in an external manager that integrates with both AWS KMS and Azure Key Vault meets the single-system-of-record goal while preserving BYOK import, policy-driven rotation, and tamper-evident audit trails. Provider-native replication or object storage cannot deliver unified control, and per-region HSM silos reintroduce fragmentation. The centralized approach also keeps key material under organizational control across clouds.

Exam trap

The trap here is assuming that a multi-Region KMS key or a replicated key vault entry creates a single multi-cloud key authority, when replication stays inside one provider.

69
MCQhard

A financial services company stores regulated data in Amazon S3 buckets. A security architect must ensure that objects are encrypted at rest using keys that the company controls, can be rotated on a schedule, and can be audited independently of AWS-managed keys. The keys must not leave AWS hardware security modules in plaintext. Which encryption option should the architect choose?

A.SSE-KMS with a customer managed key in AWS KMS
B.SSE-S3 with bucket default encryption
C.SSE-C with customer-provided keys
D.Client-side encryption before uploading to S3
AnswerA

SSE-KMS with a customer managed key lets the company define key policies, enable automatic rotation, and audit every use through CloudTrail and KMS key usage logs. The key material is protected by AWS KMS HSMs and never leaves them in plaintext. This satisfies control, scheduled rotation, and independent auditability for the regulated data.

Why this answer

SSE-KMS with a customer managed key gives the company ownership of the key policy, scheduled rotation, and an audit trail via CloudTrail and KMS logs, while the key material remains protected inside AWS KMS HSMs. This matches the control, rotation, and auditability requirements.

Exam trap

The trap here is confusing customer-controlled keys with customer-provided keys, assuming SSE-C provides the same audit and rotation benefits as a KMS customer managed key.

70
MCQhard

A cloud security engineer is implementing a data loss prevention (DLP) strategy for sensitive data stored in Amazon S3. The company must detect and prevent accidental exposure of personally identifiable information (PII) in objects uploaded by users. The engineer needs a solution that automatically scans new objects, identifies PII, and can trigger alerts or block access. Which AWS service should the engineer use?

A.AWS GuardDuty
B.Amazon Inspector
C.Amazon Macie
D.AWS Config
AnswerC

Amazon Macie is a fully managed data security and privacy service that uses machine learning to automatically discover, classify, and protect sensitive data in S3. It continuously evaluates buckets for PII and other sensitive data, providing detailed findings and alerting via EventBridge. It can also be configured to automatically remediate issues, such as blocking public access, making it the appropriate choice for this scenario.

Why this answer

Amazon Macie is purpose-built to discover and protect sensitive data in S3. It uses pattern matching and machine learning to identify PII, financial data, and credentials. It provides findings that can be integrated with Security Hub and EventBridge for automated responses.

This directly addresses the need to scan new objects, detect PII, and trigger alerts or remediation actions.

Exam trap

The trap here is confusing threat detection (GuardDuty) or configuration auditing (AWS Config) with data classification and DLP capabilities.

71
MCQmedium

A cloud engineer manages a Kubernetes cluster on Google Kubernetes Engine (GKE). An application team reports that a compromised container in the 'payments' namespace attempted to read secrets belonging to the 'analytics' namespace, but the request was denied. The engineer wants to enforce a policy that restricts pod-to-pod traffic so that only pods labeled 'app=frontend' can reach pods labeled 'app=api' on TCP port 8080, while denying all other ingress to the api pods. Which mechanism should the engineer implement?

A.A Kubernetes Service of type ClusterIP exposing the api pods, combined with a PodDisruptionBudget to limit access.
B.A GKE firewall rule (VPC firewall) that allows ingress to the node pool on TCP 8080 from the frontend node pool's IP range only.
C.An Istio sidecar with mTLS STRICT mode enabled in the payments and analytics namespaces.
D.A Kubernetes NetworkPolicy applied in the api namespace selecting pods with label app=api, with an ingress rule allowing only pods labeled app=frontend on TCP 8080.
AnswerD

NetworkPolicy is the native Kubernetes object that controls pod-level ingress and egress. Selecting app=api and permitting only app=frontend on TCP 8080 enforces the least-privilege requirement directly. On GKE, NetworkPolicy enforcement requires a policy-capable CNI (Calico or the built-in GKE Dataplane V2), which the cluster already has since the cross-namespace read was denied by a policy.

Why this answer

Kubernetes NetworkPolicy is the correct tool because it provides label-selector-based ingress control at the pod level. Selecting pods labeled app=api and allowing ingress only from app=frontend on TCP 8080 implements the required least-privilege traffic rule. Node-level VPC firewalls, Services, and mTLS alone cannot express or enforce this pod-label restriction, so the NetworkPolicy is the only option that meets the stated requirement.

Exam trap

The trap here is assuming VPC-level firewall rules or service mesh mTLS alone can restrict traffic between individual pods, when only a Kubernetes NetworkPolicy object can enforce label-based pod ingress.

72
MCQmedium

A cloud administrator is designing network security for a three-tier application. The web tier must be accessible from the internet, but the application and database tiers should only be reachable from the web tier. Which security group configuration should be used?

A.Use separate security groups: web allows HTTP/HTTPS from 0.0.0.0/0; app allows traffic from web security group; db allows traffic from app security group
B.Assign the same security group to all tiers and use a single inbound rule
C.Place all tiers in the same subnet and use a network ACL to permit all traffic
D.Configure a network ACL for each subnet with allow rules for the required traffic
AnswerA

Security groups act as stateful virtual firewalls referencing each other as sources. Chaining web-to-app and app-to-db rules restricts the application and database tiers to traffic originating from the preceding tier, satisfying the isolation constraint while exposing only the web tier publicly.

Why this answer

It uses separate security groups for each tier, implementing the principle of least privilege. The web tier security group allows HTTP/HTTPS from 0.0.0.0/0 for internet access, while the app tier security group references the web tier security group as its source, ensuring only traffic from the web tier can reach the application tier. Similarly, the database tier security group references the app tier security group, restricting access exclusively to the application tier.

This configuration enforces strict east-west traffic control and prevents direct internet access to the internal tiers.

Exam trap

A common trap is confusing the functionality of stateful security groups with stateless network ACLs. Candidates may choose network ACLs (Option D) thinking they provide similar control, not realizing that security groups support logical references to other security groups, which is essential for dynamic tier-to-tier access in a three-tier architecture.

How to eliminate wrong answers

Option B is wrong because assigning the same security group to all tiers with a single inbound rule would allow all tiers to communicate with each other without restriction, violating the principle of least privilege and potentially exposing the database tier to the web tier or the internet. Option C is wrong because placing all tiers in the same subnet and using a network ACL to permit all traffic eliminates subnet-level segmentation, allowing any instance in the subnet to reach any other instance, and network ACLs are stateless, requiring explicit return rules, which adds complexity and risk. Option D is wrong because while network ACLs can provide subnet-level filtering, they are stateless and do not support security group references as sources; they require manual IP address management and cannot dynamically reference the web tier's security group, making them less precise and harder to maintain for tier-to-tier access control.

73
MCQmedium

A cloud architect is designing a multi-tier application. The application tier needs to access a database, but the database should not be reachable from the internet. Which network security control should be used?

A.Place the database in a private subnet and use a security group to allow traffic only from the application tier
B.Encrypt the database connection using TLS
C.Use a VPN to connect the application tier to the database
D.Place the database in a public subnet with restrictive security groups
AnswerA

A private subnet removes the database from internet routing, while a security group referencing the application tier as source enforces least-privilege access at the instance level. Together they satisfy the constraint that only the application tier may reach the database.

Why this answer

Placing the database in a private subnet with no direct internet route ensures it is not reachable from the internet. Security groups can then allow inbound traffic only from the application tier's security group.

74
MCQmedium

An organization wants to ensure that only authenticated users from their corporate Active Directory can access cloud resources. Which federation protocol is most commonly used for this purpose?

A.LDAP
B.OAuth 2.0
C.RADIUS
D.SAML
AnswerD

SAML exchanges signed assertions between the corporate identity provider and the cloud service, so Active Directory credentials authenticate users without replicating accounts. This satisfies the requirement that only authenticated corporate AD users reach cloud resources, unlike OAuth, which handles authorisation delegation rather than federated authentication.

Why this answer

SAML (Security Assertion Markup Language) is the standard federation protocol used to enable single sign-on (SSO) between an identity provider (like Active Directory Federation Services) and a service provider (cloud resources). It exchanges authentication and authorization data in XML assertions, allowing users authenticated against corporate AD to access cloud applications without separate credentials. SAML is specifically designed for web-based federated identity scenarios, making it the most common choice for enterprise cloud SSO.

Exam trap

CV0-004 often tests the confusion between authentication and authorization protocols — candidates may pick OAuth 2.0 thinking it handles login, but OAuth is for delegated authorization, while SAML is the federation standard for SSO.

How to eliminate wrong answers

Option A is wrong because LDAP is a directory access protocol used for querying and modifying directory services, not a federation protocol for cross-domain authentication; it does not support web SSO assertions. Option B is wrong because OAuth 2.0 is an authorization framework for delegated access (e.g., allowing an app to access resources on a user's behalf), not an authentication or federation protocol for verifying user identity across domains. Option C is wrong because RADIUS is a network access authentication protocol used for VPNs, Wi-Fi, and dial-up, not for federating identities to cloud applications.

75
MCQeasy

In the shared responsibility model, which of the following is the cloud customer responsible for?

A.Operating system patching on virtual machines
B.Network infrastructure under the hypervisor
C.Hypervisor security
D.Physical hardware maintenance
AnswerA

In IaaS, the provider secures the physical hosts, hypervisor and network fabric, while the customer retains control of guest operating systems. Patching those VMs is therefore the customer's responsibility, satisfying the shared responsibility split at the OS layer.

Why this answer

In the shared responsibility model, the cloud customer is responsible for security 'in' the cloud, which includes the operating system, applications, and data. For IaaS, the customer manages the guest OS, including patching, while the cloud provider manages the hypervisor, network infrastructure, and physical hardware. Therefore, operating system patching on virtual machines is the customer's responsibility.

Exam trap

The trap here is confusing the responsibilities across service models. Candidates might think the provider handles OS patching in IaaS, but that's only true for PaaS or SaaS. Always remember: in IaaS, you patch the OS.

How to eliminate wrong answers

Option B is wrong because network infrastructure under the hypervisor is managed by the cloud provider. Option C is wrong because hypervisor security is the cloud provider's responsibility. Option D is wrong because physical hardware maintenance is handled by the cloud provider.

Page 1 of 2 · 121 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Security questions.