Courseiva

CCNA Security Questions

46 of 121 questions · Page 2/2 · Security · Answers revealed

76
Multi-Selecthard

A company is deploying a cloud-native application that uses containers orchestrated by Kubernetes. The security team wants to enforce the principle of least privilege at the Kubernetes level. Which THREE measures should be implemented? (Choose three.)

Select 3 answers
A.Apply Pod Security Standards (e.g., restricted policy)
B.Implement Kubernetes RBAC to restrict permissions to namespaces and resources
C.Implement network policies to restrict pod-to-pod communication
D.Create service accounts with only the necessary permissions for each application
E.Use namespaces to separate environments
AnswersA, B, D

Pod Security Standards enforce security contexts that limit pod capabilities.

Why this answer

Pod Security Standards (PSS) define security contexts for pods, with the 'restricted' policy enforcing the principle of least privilege by disallowing privileged containers, host network access, and other high-risk capabilities. This directly prevents pods from running with unnecessary permissions, aligning with the security team's goal at the pod level.

Exam trap

The CV0-004 exam often tests the distinction between network-level controls (network policies) and identity/privilege controls (RBAC, Pod Security Standards), leading candidates to mistakenly select network policies as a least-privilege measure when they only restrict traffic, not permissions.

77
MCQeasy

A security administrator needs to store database credentials and API keys securely in AWS. The credentials must be automatically rotated every 90 days. Which service should the administrator use?

A.AWS Systems Manager Parameter Store
B.AWS KMS
C.AWS Secrets Manager
D.AWS Certificate Manager
AnswerC

AWS Secrets Manager natively stores and encrypts secrets, and its built-in rotation schedules Lambda functions to change credentials automatically. This directly satisfies the stem's 90-day rotation requirement, which AWS Systems Manager Parameter Store cannot perform without custom automation.

Why this answer

AWS Secrets Manager is designed to store secrets and provides built-in rotation capabilities.

78
Multi-Selecthard

A cloud security team is reviewing a Google Cloud environment. They need to ensure that data stored in Cloud Storage buckets is protected with customer-managed encryption keys and that access to those keys is tightly controlled. Which TWO actions should the team take? (Choose two.)

Select 2 answers
A.Enable uniform bucket-level access on the bucket.
B.Use customer-supplied encryption keys (CSEK) by providing the key with each upload request.
C.Create a Cloud KMS key ring and key, then grant the storage service account the cryptoKeyEncrypterDecrypter role on the key.
D.Configure the bucket's default encryption to use the Cloud KMS key.
E.Create a service account with the Cloud KMS Admin role and use it to encrypt all objects manually.
AnswersC, D

To use customer-managed encryption keys (CMEK) with Cloud Storage, you must create a Cloud KMS key and grant the Cloud Storage service account permission to use it. The cryptoKeyEncrypterDecrypter role allows the service to encrypt and decrypt data with the key. This is a required step for enabling CMEK on buckets.

Why this answer

Enabling CMEK for Cloud Storage requires creating a Cloud KMS key and granting the Cloud Storage service account the cryptoKeyEncrypterDecrypter role on that key. Then, the bucket's default encryption must be set to use that key. These two actions ensure that objects are encrypted with customer-managed keys and that access to the keys is controlled via IAM.

Exam trap

The trap here is confusing customer-managed encryption keys (CMEK) with customer-supplied encryption keys (CSEK), which are provided per request and not managed in Cloud KMS.

79
MCQhard

A security administrator is configuring a Web Application Firewall (WAF) to protect a public-facing web application. The application experiences a high volume of traffic from certain geographic regions that are not serving customers. Which WAF feature should be used to block this traffic?

A.Rate limiting
B.OWASP rule set
C.Geo-blocking
D.IP reputation lists
AnswerC

Geo-blocking inspects the source IP's geographic origin and denies requests from specified countries or regions, directly satisfying the requirement to drop traffic from regions that generate no customers. It filters at the WAF layer before requests reach the application, unlike rate limiting or signature-based rules.

Why this answer

Geo-blocking allows the WAF to block or allow traffic based on geographic location, reducing unwanted traffic and potential attacks.

80
MCQhard

A company uses Azure RBAC to manage access to resources. A user is assigned a Contributor role at the subscription scope. Which of the following is true regarding the scope of this role?

A.The user will have Contributor permissions only on resources created after the assignment.
B.The user will have Contributor permissions on the subscription itself but not its resources.
C.The user will have Contributor permissions only on resource groups within the subscription.
D.The user will have Contributor permissions on all resources within the subscription.
AnswerD

Azure RBAC assignments are inherited by every child scope, so a Contributor role granted at subscription level flows down to all resource groups and resources inside that subscription. This satisfies the stem's subscription-scope constraint, rather than limiting access to a single resource group or resource.

Why this answer

RBAC roles in Azure are inherited from higher scopes to lower scopes (management group → subscription → resource group → resource).

81
MCQeasy

A cloud administrator needs to grant a developer read-only access to a specific storage bucket in AWS. Which IAM component should the administrator modify?

A.IAM policy
B.Security group
C.AWS WAF
D.Network ACL
AnswerA

An IAM policy is the JSON document that defines which actions are allowed or denied on specified resources, and attaching a read-only policy to the developer's identity or the bucket grants exactly that scoped access. Roles, groups and ACLs alone cannot express this permission set.

Why this answer

To grant a developer read-only access to a specific S3 bucket, the administrator must modify an IAM policy. IAM policies are JSON documents that define permissions (Allow/Deny) for actions on AWS resources, and they can be attached to IAM users, groups, or roles. By creating a policy that allows s3:GetObject, s3:ListBucket, etc., on the specific bucket ARN, the administrator can grant least-privilege read-only access.

Exam trap

The trap is confusing network-level controls (security groups, NACLs, WAF) with identity and access management (IAM). Candidates may think that a security group can restrict S3 access, but S3 is not a VPC resource and security groups do not apply to it.

How to eliminate wrong answers

Option B is wrong because security groups act as virtual firewalls for EC2 instances and other resources at the network layer; they control inbound and outbound traffic based on IP, port, and protocol, not IAM permissions for S3. Option C is wrong because AWS WAF is a web application firewall that protects web applications from common exploits; it does not manage identity-based access to S3 buckets. Option D is wrong because network ACLs are stateless subnet-level firewalls that control traffic in and out of subnets; they do not grant or deny IAM permissions to S3.

82
MCQhard

A financial services firm runs containerized workloads on a managed Kubernetes service. Auditors require that no container can run as root, that privilege escalation is blocked, and that the policy is enforced at admission time without modifying existing deployment manifests. Which control best meets these requirements?

A.Deploy a runtime security agent that kills containers detected running with root privileges.
B.Configure a Pod Security Admission policy with the restricted profile applied to the target namespace.
C.Enable the Kubernetes audit log and forward events to a SIEM for alerting on privileged containers.
D.Apply a network policy that denies egress traffic from containers running in the target namespace.
AnswerB

Pod Security Admission enforces pod security standards at admission time and the restricted profile blocks root execution, privilege escalation, and other unsafe capabilities. Applying it to the namespace enforces the policy without editing individual deployment manifests, and violations are rejected before the pod is created. This directly satisfies the auditor's enforcement and non-modification requirements.

Why this answer

Pod Security Admission enforces pod security standards when a pod is admitted, so the restricted profile prevents root execution and privilege escalation before the container starts. It applies at the namespace level, requiring no changes to deployment manifests. Logging, network policy, and runtime termination either observe or react rather than block, so they cannot satisfy a preventive admission-time mandate.

Exam trap

The trap here is treating runtime detection or audit logging as equivalent to admission-time enforcement, when only an admission controller can reject a non-compliant pod before it runs.

83
MCQhard

A company uses Azure and wants to enforce multi-factor authentication (MFA) for all administrative users. The solution must be centrally managed and apply to all Azure subscriptions. Which approach should be used?

A.Create a Conditional Access policy in Azure AD requiring MFA for all cloud apps
B.Configure MFA on each individual Azure subscription
C.Assign MFA to each user individually in Azure AD
D.Use Azure Policy to require MFA for admin roles
AnswerA

Conditional Access in Microsoft Entra ID evaluates sign-in signals and enforces MFA tenant-wide, covering every Azure subscription because subscriptions inherit directory-level authentication. This satisfies the central management constraint: one policy applies to all administrative users across all cloud apps, rather than per-subscription configuration.

Why this answer

Conditional Access policies in Azure AD are centrally managed and can enforce MFA for all cloud apps across all Azure subscriptions by targeting the 'Microsoft Azure Management' cloud app. This approach applies to all administrative users regardless of subscription, as Azure AD is the identity provider for Azure resources.

Exam trap

The trap here is confusing Azure Policy (resource compliance) with Azure AD Conditional Access (identity security), leading candidates to select Option D, even though Azure Policy cannot enforce authentication requirements.

How to eliminate wrong answers

Option B is wrong because MFA cannot be configured on individual Azure subscriptions; MFA is an Azure AD feature, not a subscription-level setting. Option C is wrong because assigning MFA per user is not centrally managed and does not scale to apply to all subscriptions automatically; it also lacks the granularity of Conditional Access policies. Option D is wrong because Azure Policy is used for resource compliance (e.g., tagging, encryption) and cannot enforce MFA, which is an identity-level control managed by Azure AD.

84
MCQhard

A company uses Google Cloud Platform (GCP) and wants to enforce that all service accounts used by applications have only the permissions necessary to perform their tasks. Which IAM concept should the administrator apply?

A.Separation of duties
B.Privileged access management (PAM)
C.Role-based access control (RBAC)
D.Least privilege
AnswerD

Least privilege grants each service account only the IAM roles its task requires, nothing broader. Applied through predefined or custom roles on GCP, it directly satisfies the stem's constraint that service accounts hold only the permissions necessary for their work.

Why this answer

The principle of least privilege dictates granting only the required permissions. In GCP, this is achieved by assigning predefined roles that are narrowly scoped to specific services, and by using conditions to further restrict access.

85
MCQeasy

A cloud engineer is configuring a web application on AWS and needs to ensure that only HTTP and HTTPS traffic from the internet is allowed to reach the EC2 instances. Which AWS service should be used to control inbound traffic at the instance level?

A.Security Group
B.AWS Shield
C.AWS WAF
D.Network ACL
AnswerA

Security groups are stateful virtual firewalls attached directly to EC2 elastic network interfaces, so rules are evaluated per instance rather than per subnet. Allowing only TCP ports 80 and 443 inbound satisfies the instance-level constraint, with return traffic automatically permitted regardless of outbound rules.

Why this answer

Security groups are stateful virtual firewalls that control inbound and outbound traffic at the instance level. Network ACLs operate at the subnet level and are stateless.

86
MCQmedium

A security administrator is configuring a web application firewall (WAF) to protect against SQL injection attacks. Which WAF feature should be enabled?

A.Geo-blocking
B.Rate limiting
C.OWASP rule set
D.DDoS protection
AnswerC

The OWASP rule set supplies preconfigured signatures that detect and block SQL injection patterns in inbound requests, directly satisfying the requirement to protect the web application. Unlike generic rate limiting or IP reputation, these rules inspect payload syntax against known injection techniques, so enabling the OWASP core rule set on the WAF mitigates the attack class named in the stem.

Why this answer

The OWASP rule set (also called OWASP Core Rule Set, CRS) is a collection of generic attack detection rules specifically designed to protect web applications against the OWASP Top 10, including SQL injection, cross-site scripting, and command injection. Enabling it on a WAF provides immediate, well-tested signatures for SQLi patterns. This directly addresses the requirement to protect against SQL injection.

Exam trap

CV0-004 often tests WAF feature selection, and the trap is choosing rate limiting or geo-blocking because they sound like security controls, when only the OWASP rule set actually inspects request payloads for SQL injection patterns.

How to eliminate wrong answers

Option A is wrong because geo-blocking restricts traffic based on geographic origin and does nothing to detect or block SQL injection payloads in HTTP requests. Option B is wrong because rate limiting controls request volume to mitigate brute-force or DoS attacks but does not inspect request content for SQLi syntax. Option D is wrong because DDoS protection mitigates volumetric and protocol-layer attacks, not application-layer injection attacks like SQLi.

87
MCQmedium

An organization uses multiple cloud providers and wants to centralize secrets management. Which solution would best meet this requirement?

A.Azure Key Vault
B.AWS Secrets Manager
C.HashiCorp Vault
D.Google Cloud Secret Manager
AnswerC

HashiCorp Vault is cloud-agnostic, running centrally to issue and audit secrets across AWS, Azure and Google Cloud through one API. This satisfies the multi-cloud centralisation constraint, whereas native secret managers such as Azure Key Vault remain scoped to their own provider.

Why this answer

HashiCorp Vault is a multi-cloud secrets management solution that can store and rotate secrets across different providers.

88
MCQeasy

An organization wants to audit all API calls made in their AWS account. Which AWS service should be enabled to capture these logs?

A.Amazon CloudWatch
B.AWS Trusted Advisor
C.AWS CloudTrail
D.AWS Config
AnswerC

CloudTrail records API activity in an AWS account, capturing the identity of the caller, timestamp, source IP and request parameters for every call. Enabling it satisfies the requirement to audit all API calls, since CloudWatch monitors metrics and Config tracks resource state rather than API events.

Why this answer

AWS CloudTrail records API activity for governance, compliance, and auditing.

89
MCQmedium

An organization uses Azure and wants to ensure that only authenticated users from its on-premises Active Directory can access cloud resources. The company has Azure AD Connect set up and wants to enable single sign-on (SSO) for cloud applications. Which federation standard should be used?

A.Kerberos
B.OAuth 2.0
C.SAML
D.OpenID Connect
AnswerC

SAML is the federation standard that Microsoft Entra ID uses to exchange authentication assertions with cloud applications, enabling SSO for users synced from on-premises Active Directory via Azure AD Connect. It satisfies the requirement for authenticated on-premises users accessing cloud resources without separate credentials.

Why this answer

SAML (Security Assertion Markup Language) is the correct federation standard because it enables browser-based single sign-on (SSO) by exchanging authentication and authorization assertions between an identity provider (on-premises Active Directory via Azure AD Connect) and a service provider (cloud applications). SAML 2.0 is specifically designed for federated identity scenarios where users authenticate on-premises and gain access to cloud resources without re-entering credentials.

Exam trap

The trap here is that candidates confuse OAuth 2.0 or OpenID Connect as the default for all SSO scenarios, but the question specifically describes a traditional on-premises AD federation with browser-based cloud applications, which is the classic SAML use case.

How to eliminate wrong answers

Option A is wrong because Kerberos is a network authentication protocol that uses tickets and is designed for on-premises environments, not for federated SSO across cloud boundaries; it cannot pass assertions to cloud applications. Option B is wrong because OAuth 2.0 is an authorization framework, not an authentication protocol; it does not provide identity assertions or user authentication information by itself. Option D is wrong because OpenID Connect is built on top of OAuth 2.0 for authentication but is primarily used for modern web and mobile applications with RESTful APIs, not for the traditional browser-based SAML federation pattern that Azure AD Connect uses for SSO with on-premises AD.

90
MCQeasy

Which of the following is the cloud provider's responsibility under the shared responsibility model?

A.Encrypting data stored in cloud resources
B.Configuring identity and access management policies
C.Securing the physical data center
D.Patching guest operating systems
AnswerC

Securing the physical data centre falls entirely to the cloud provider, satisfying the shared responsibility model's division where the provider always owns physical security. Customers cannot access or harden buildings, racks, or hardware, so this control never transfers to them, unlike patching, identity, or data classification.

Why this answer

Under the shared responsibility model, the cloud provider is responsible for security 'of' the cloud, which includes the physical data center, hardware, and infrastructure. Securing the physical data center is solely the provider's responsibility. The customer is responsible for security 'in' the cloud, such as data encryption, IAM policies, and guest OS patching.

Exam trap

The trap is confusing responsibilities that are always the customer's (like encryption and IAM) with those that are the provider's (physical security); candidates may overestimate the provider's role in data security.

How to eliminate wrong answers

Option A is wrong because encrypting data stored in cloud resources is a customer responsibility, as the customer controls encryption keys and data classification. Option B is wrong because configuring IAM policies is a customer responsibility, as the customer manages access to their resources. Option D is wrong because patching guest operating systems is a customer responsibility, as the customer controls the OS and its updates.

91
MCQhard

A security administrator needs to enforce least privilege for a Kubernetes cluster in a cloud environment. Which approach should be used to restrict permissions for pods that need to access the cloud provider's API?

A.Assign the pod a static cloud IAM user credential
B.Disable cloud API access for all pods
C.Use a service account with a role that has only the required permissions
D.Grant the pod cluster-admin privileges in Kubernetes
AnswerC

A Kubernetes service account mapped to a cloud role grants pods only the permissions that role defines, satisfying least privilege for API access. Unlike node-wide instance profiles, which expose every pod on that node to the same credentials, this binds permissions to the workload identity itself, so each pod receives solely its required scope.

Why this answer

In Kubernetes, pods assume a Kubernetes service account, and cloud providers support mapping that service account to a cloud IAM role via workload identity (for example, IRSA on EKS or Workload Identity on GKE/AKS). This lets the pod obtain short-lived credentials scoped to only the permissions in the role, enforcing least privilege without embedding static credentials.

Exam trap

CV0-004 often tests the misconception that assigning a static IAM user to a pod is acceptable, when least privilege requires short-lived, role-based workload identity.

How to eliminate wrong answers

Option A is wrong because a static cloud IAM user credential embedded in the pod is a long-lived secret that violates least privilege and is hard to rotate. Option B is wrong because disabling cloud API access for all pods is overly restrictive and breaks legitimate workloads that need scoped access. Option D is wrong because cluster-admin privileges grant full control over the Kubernetes cluster, which is the opposite of least privilege and does not scope cloud API permissions.

92
MCQmedium

A company uses AWS and wants to centralize security monitoring across multiple accounts. Which service should they use to aggregate security findings and check compliance against standards like CIS AWS Foundations?

A.AWS CloudTrail
B.Amazon GuardDuty
C.AWS Security Hub
D.AWS Config
AnswerC

AWS Security Hub aggregates findings from GuardDuty, Inspector, Macie and other accounts into one view, and runs automated compliance checks against standards including CIS AWS Foundations Benchmark. This satisfies the requirement to centralise security monitoring and compliance across multiple accounts.

Why this answer

AWS Security Hub is a centralized security and compliance service that aggregates findings from multiple AWS services (like GuardDuty, Inspector, Macie) and third-party tools across accounts, and it runs automated compliance checks against standards such as CIS AWS Foundations, AWS Foundational Security Best Practices, and PCI DSS. It is purpose-built for cross-account security aggregation and compliance monitoring, making it the correct choice.

Exam trap

CV0-004 often tests whether candidates confuse Security Hub (aggregation and compliance) with GuardDuty (threat detection) or Config (configuration assessment) — each serves a distinct role in the AWS security ecosystem.

How to eliminate wrong answers

Option A is wrong because AWS CloudTrail records API activity and account events for auditing, but it does not aggregate security findings or check compliance against standards — it is a logging service, not a security posture service. Option B is wrong because Amazon GuardDuty is a threat detection service that identifies malicious activity and unauthorized behavior, but it does not aggregate findings across services or perform compliance checks against standards like CIS. Option D is wrong because AWS Config assesses, audits, and evaluates the configurations of AWS resources against desired configurations, but it does not aggregate security findings from other services or provide a centralized compliance dashboard across accounts.

93
MCQhard

A cloud security engineer is responsible for an AWS environment that stores regulated data in Amazon S3 buckets. An audit finding states that data at rest in S3 is not encrypted with a customer-managed key, and the organization must retain control over key rotation and access policies. The engineer must implement encryption that satisfies the audit while minimizing changes to existing applications. Which approach should the engineer take?

A.Enable SSE-C by providing encryption keys in each S3 API request.
B.Enable S3 default encryption using SSE-S3 (AES-256) on all buckets.
C.Implement client-side encryption in each application before uploading objects to S3.
D.Configure SSE-KMS with a customer-managed AWS KMS key and set the bucket default encryption to use that key.
AnswerD

SSE-KMS with a customer-managed key lets the organization define key policies, control rotation, and audit key usage via CloudTrail. Setting it as the bucket default ensures new objects are encrypted automatically without application changes. This satisfies the audit requirement for customer-managed keys while minimizing disruption.

Why this answer

SSE-KMS with a customer-managed key gives the organization control over key policies, rotation, and usage auditing while allowing S3 to handle encryption transparently. Setting it as the bucket default means applications do not need modification to encrypt new objects. Other options either leave key control with AWS or require significant application changes.

Exam trap

The trap here is equating any S3 encryption with compliance, when the audit specifically demands customer-managed keys and control over rotation, which only SSE-KMS with a customer-managed key provides.

94
MCQmedium

A financial services company runs a critical application on Google Cloud. The security team requires that all data at rest in Cloud Storage buckets be encrypted with customer-managed encryption keys (CMEK) that are rotated every 90 days. The company also needs to maintain full control over key lifecycle and revoke access immediately if a key is compromised. Which GCP service should be used to manage these keys?

A.Cloud Identity and Access Management (IAM)
B.Cloud Hardware Security Module (Cloud HSM)
C.Cloud Data Loss Prevention (DLP)
D.Cloud Key Management Service (Cloud KMS)
AnswerD

Cloud KMS allows organizations to create and manage customer-managed encryption keys (CMEK) for Cloud Storage and other services. It supports automatic rotation schedules (e.g., every 90 days) and provides granular IAM controls to revoke access instantly. The key material is stored in a hardware security module (HSM) or software, and the customer retains full control, meeting all requirements.

Why this answer

Cloud KMS is the centralized key management service in GCP. It enables the creation of CMEK, supports automatic rotation schedules, and integrates with Cloud Storage to encrypt data at rest. Access to keys is controlled via IAM, allowing immediate revocation.

This provides the required control over key lifecycle and meets the 90-day rotation policy.

Exam trap

The trap here is assuming that Cloud HSM alone provides key management, when it is actually a key storage option within Cloud KMS.

95
MCQeasy

Which of the following compliance frameworks is specifically designed for handling healthcare information in the United States?

A.SOC 2 Type II
B.ISO 27001
C.PCI DSS
D.HIPAA
AnswerD

HIPAA, the Health Insurance Portability and Accountability Act, governs protected health information held by US covered entities and business associates. It specifies administrative, physical and technical safeguards plus breach notification, making it the framework specifically designed for US healthcare data handling.

Why this answer

HIPAA (Health Insurance Portability and Accountability Act) sets standards for protecting sensitive patient data. PCI DSS is for payment card data, SOC 2 is for service organizations, ISO 27001 is for information security management.

96
Multi-Selecthard

A cloud security team is implementing encryption for data at rest using customer-managed keys in a cloud KMS. Which THREE practices should be followed?

Select 3 answers
A.Use IAM policies to restrict who can use and manage the keys.
B.Enable automatic key rotation.
C.Store the key material in plaintext in the application code.
D.Use a default cloud provider key to simplify management.
E.Back up the key material securely in a separate location.
AnswersA, B, E

IAM controls access to KMS keys.

Why this answer

IAM policies are essential for enforcing the principle of least privilege in cloud KMS. By restricting who can use (encrypt/decrypt) and manage (rotate/disable/destroy) customer-managed keys, the security team ensures that only authorized principals can access the key material. This prevents unauthorized users or services from compromising data at rest, which is a core requirement for compliance frameworks like PCI DSS or HIPAA.

Exam trap

The CV0-004 exam often tests the misconception that storing keys in code is acceptable if the code is in a private repository, but the trap here is that any plaintext key in code is a critical vulnerability, regardless of repository access controls.

97
MCQeasy

A cloud architect is designing a multi-tenant SaaS application on AWS. Which of the following security responsibilities is the CUSTOMER responsible for under the shared responsibility model?

A.Global network infrastructure
B.Patching the hypervisor
C.Physical security of data centers
D.Configuring security groups
AnswerD

Security groups are a customer-configurable network security control.

Why this answer

Under the shared responsibility model, the customer is responsible for data encryption, OS patching, and IAM configuration, while the provider secures the physical infrastructure.

98
MCQhard

A DevOps team deploys a containerized application on Amazon EKS. The security team wants to ensure that containers do not run as root and that read-only root filesystems are enforced. Which Kubernetes mechanism should be used?

A.Pod Security Standards
B.Kubernetes RBAC
C.Network Policies
D.Secrets management
AnswerA

Pod Security Standards enforce security constraints at the pod level.

Why this answer

Pod Security Standards (formerly PSP) define security contexts, including runAsNonRoot and readOnlyRootFilesystem, to enforce these policies.

99
MCQmedium

A cloud administrator needs to provide external partners with access to a cloud application using their existing corporate credentials. Which federation protocol should be used?

A.RADIUS
B.Kerberos
C.SAML
D.LDAP
AnswerC

SAML exchanges signed assertions between the partner's identity provider and the cloud application, letting partners authenticate with existing corporate credentials. It is the established browser-based federation standard for external access, avoiding separate accounts for each partner.

Why this answer

SAML (Security Assertion Markup Language) is the standard federation protocol for web-based single sign-on, allowing external partners to authenticate with their own corporate identity provider and access a cloud application via trust relationships. It exchanges XML-based assertions between an identity provider and a service provider. This matches the requirement of using existing corporate credentials for external access.

Exam trap

The trap is selecting LDAP or Kerberos because they are familiar authentication technologies; candidates overlook that federation across organizational boundaries to a cloud app specifically requires SAML (or OIDC), not directory or network authentication protocols.

How to eliminate wrong answers

Option A is wrong because RADIUS is an AAA protocol used primarily for network access authentication (VPN, Wi-Fi, dial-up), not for web application federation or cross-domain SSO. Option B is wrong because Kerberos is a ticket-based authentication protocol designed for intra-domain use within a trusted realm (e.g., Active Directory), not for federating identities across organizational boundaries to cloud apps. Option D is wrong because LDAP is a directory access protocol for querying and modifying directory services; it does not provide the federated trust and assertion exchange needed for cross-organization SSO.

100
MCQhard

A cloud engineer is deploying a containerized application on Amazon EKS. The application pods need to access an Amazon RDS database. The security team wants to avoid storing database credentials in the container image or environment variables and prefers short-lived credentials. Which mechanism should be used?

A.AWS Secrets Manager with IAM roles for service accounts (IRSA)
B.Kubernetes Secrets mounted as environment variables
C.AWS Systems Manager Parameter Store with SecureString parameters
D.Amazon RDS IAM database authentication with a static master password
AnswerA

IAM roles for service accounts (IRSA) allows Kubernetes pods to assume an IAM role and obtain temporary credentials. The pod can then retrieve the database secret from AWS Secrets Manager using those credentials, avoiding hardcoded secrets. This provides short-lived credentials and fine-grained access control, directly meeting the security team's requirements for the EKS application.

Why this answer

IAM roles for service accounts (IRSA) enables EKS pods to assume an IAM role and receive temporary credentials. The pod can then access AWS Secrets Manager to retrieve the database secret dynamically, eliminating hardcoded credentials. This approach provides short-lived credentials and adheres to the security team's preference for avoiding static secrets in the container environment.

Exam trap

The trap here is believing that Kubernetes Secrets or Parameter Store alone solve credential management, when they still require a secure, short-lived identity to access them.

101
MCQeasy

Which encryption standard is most commonly used for data at rest in cloud storage services?

A.Blowfish
B.DES
C.AES-256
D.RSA
AnswerC

AES-256 is the symmetric block cipher overwhelmingly adopted for cloud data-at-rest encryption, offering 256-bit keys resistant to brute force. It satisfies the stem's requirement for the encryption standard most commonly used by cloud storage services.

Why this answer

AES-256 is the de facto standard for data-at-rest encryption in cloud storage services such as Amazon S3, Azure Blob Storage, and Google Cloud Storage. It provides strong symmetric encryption with a 256-bit key, is FIPS 140-2/3 validated, and is widely supported by hardware acceleration. Cloud providers default to AES-256 (or AES-128 in some cases) for server-side encryption.

Exam trap

CV0-004 often tests the confusion between symmetric encryption algorithms (AES) used for bulk data-at-rest and asymmetric algorithms (RSA) used for key exchange or signatures — candidates may pick RSA thinking 'stronger equals better' for storage.

How to eliminate wrong answers

Option A is wrong because Blowfish is a legacy symmetric cipher with a 64-bit block size that is considered outdated and is not used as a cloud storage default. Option B is wrong because DES (and 3DES) has a 56-bit effective key and is cryptographically broken for modern use; no major cloud provider uses it for data-at-rest. Option D is wrong because RSA is an asymmetric algorithm used for key exchange and digital signatures, not for bulk data-at-rest encryption — it is far too slow for encrypting large datasets.

102
MCQeasy

A cloud engineer is configuring an Azure Storage account that holds regulated customer data. The compliance team requires that data is encrypted at rest with customer-managed keys stored in Azure Key Vault, and that key usage is auditable. Which configuration should the engineer apply?

A.Configure a customer-managed key in Azure Key Vault and assign it as the encryption key for the storage account.
B.Set the storage account encryption key source to Microsoft-managed keys and enable soft delete.
C.Enable infrastructure encryption and store keys in a managed HSM.
D.Enable Azure Disk Encryption on the storage account and store the KEK in Key Vault.
AnswerA

Azure Storage supports customer-managed keys by referencing a key in Key Vault or Managed HSM. Setting the account's encryption key source to the Key Vault key makes the customer control rotation and revocation, and Key Vault diagnostic logs record key operations for audit, satisfying the regulated-data requirement.

Why this answer

Azure Storage encryption supports customer-managed keys by referencing a key stored in Azure Key Vault or Managed HSM. Setting the account's encryption key source to that key gives the customer control over rotation and revocation, while Key Vault logging records every key operation. Microsoft-managed keys and disk encryption do not provide the same customer control or auditability for storage account data.

Exam trap

The trap here is applying Azure Disk Encryption, which protects VM disks, to an Azure Storage account that stores blobs and files.

103
MCQeasy

A company stores sensitive customer data in an Amazon S3 bucket. A security audit reveals that the data is encrypted at rest using SSE-S3. The company now requires that they manage and control the encryption keys themselves, including the ability to rotate and revoke them. Which S3 encryption option should be used?

A.Client-side encryption
B.SSE-S3
C.SSE-KMS with AWS managed keys
D.SSE-KMS with customer managed keys
AnswerD

SSE-KMS with customer managed keys allows the organization to create and control the KMS keys used for S3 encryption. The customer can define key policies, enable automatic rotation, and disable or revoke keys when needed. This satisfies the requirement for full control over key management, including rotation and revocation, while still using S3 server-side encryption.

Why this answer

SSE-KMS with customer managed keys gives the organization ownership and control of the KMS keys used to encrypt S3 objects. This allows key rotation, policy management, and revocation, which aligns with the audit requirement. Other S3 encryption options either lack customer key control or place management outside the S3 server-side encryption model.

Exam trap

The trap here is assuming that any KMS-based encryption gives full customer control, when AWS managed keys do not permit rotation or revocation by the customer.

104
MCQeasy

A cloud customer is deploying a virtual machine (VM) in a public IaaS environment. According to the shared responsibility model, which of the following security tasks is the customer responsible for?

A.Securing the hypervisor
B.Patching the guest operating system
C.Physical security of the data center
D.Network infrastructure integrity
AnswerB

In IaaS, the provider secures the physical hosts, hypervisor and network fabric, while the customer owns everything above it, including the guest operating system. Patching that guest OS therefore falls to the customer, satisfying the shared responsibility split for this deployment.

Why this answer

In the shared responsibility model for IaaS, the cloud provider is responsible for the security 'of' the cloud (physical security, hypervisor, network infrastructure), while the customer is responsible for security 'in' the cloud. Patching the guest operating system is a customer task because the customer has full control over the VM's OS, including updates, configuration, and application security. This aligns with the principle that the customer manages everything from the OS up, while the provider manages the virtualization layer and below.

Exam trap

CV0-004 often tests the misconception that the cloud provider handles all security tasks, leading candidates to incorrectly select physical security or hypervisor protection as customer responsibilities.

How to eliminate wrong answers

Option A is wrong because securing the hypervisor is the cloud provider's responsibility; the hypervisor is part of the virtualization infrastructure that the provider manages and isolates. Option C is wrong because physical security of the data center is always the cloud provider's responsibility, as customers have no access to or control over the physical facilities. Option D is wrong because network infrastructure integrity (e.g., routers, switches, physical network) is managed by the cloud provider; the customer is responsible for logical network security such as security groups and firewalls, but not the underlying infrastructure.

105
Multi-Selecthard

A security engineer is designing a data classification policy for a cloud environment. The policy must identify sensitive data, apply appropriate controls, and monitor access. Which THREE of the following should be included in the policy? (Select THREE.)

Select 3 answers
A.Cloud Access Security Broker (CASB) for all data
B.Encryption at rest for classified data
C.Access logging and monitoring for sensitive data
D.Network security groups to isolate data
E.Data discovery and classification tools
AnswersB, C, E

Protects data in storage.

Why this answer

Data classification includes identifying where data resides, encrypting it, and monitoring access. DLP tools help enforce policies. Security groups are network controls, not data classification.

CASB is for SaaS, but not necessarily part of a classification policy.

106
MCQeasy

Which of the following is a benefit of using a Cloud Access Security Broker (CASB) for SaaS applications?

A.It encrypts data at rest in cloud storage.
B.It provides a virtual private network (VPN) for remote access.
C.It replaces the need for a web application firewall.
D.It gives visibility and control over Shadow IT and data protection.
AnswerD

A CASB sits between users and SaaS providers, discovering unsanctioned applications and enforcing data-loss prevention, encryption and access policies. This directly delivers the visibility and control over Shadow IT and data protection that the question asks for as the SaaS benefit.

Why this answer

CASBs provide visibility into SaaS usage and enforce security policies, such as data loss prevention (DLP) and access control.

107
Multi-Selecthard

A cloud security architect is designing a data protection strategy for a multi-tenant SaaS application hosted in a public cloud. The application stores tenant data in object storage and a managed relational database. Regulators require that each tenant's data be cryptographically isolated so that a key compromise for one tenant cannot expose another tenant's data, and that the organization be able to prove key usage is auditable. Which TWO measures should the architect implement? (Choose two.)

Select 2 answers
A.Enable provider-managed encryption at rest on the object storage and database, relying on the provider's default keys.
B.Store all tenant data in a single database schema and rely on application-level row filtering for isolation.
C.Use a separate customer-managed key per tenant in a managed key management service, with key usage logged to an audit trail.
D.Implement envelope encryption where each tenant has a data key wrapped by a tenant-specific master key stored in the KMS.
E.Encrypt backups with a single organization-wide key and rotate it annually to limit exposure.
AnswersC, D

A distinct customer-managed key per tenant provides cryptographic isolation, so a compromised key affects only one tenant. Managed KMS services such as AWS KMS, Azure Key Vault, or Cloud KMS log key usage to CloudTrail, Azure Monitor, or Cloud Audit Logs, giving the auditor the required evidence. This directly satisfies both the isolation and auditability requirements.

Why this answer

Per-tenant customer-managed keys in a managed KMS provide cryptographic isolation, and envelope encryption with tenant-specific master keys ensures data keys are wrapped uniquely per tenant. Both approaches rely on KMS audit logging to prove key usage. Shared provider-managed keys, row-level filtering, and a single organization-wide key fail to create per-tenant cryptographic boundaries or auditable key-usage records.

Exam trap

The trap here is treating logical isolation, such as row filtering or a single shared key, as equivalent to cryptographic isolation with per-tenant keys and auditable usage.

108
MCQhard

A DevOps team deploys a containerized application to a Kubernetes cluster. They need to ensure that containers cannot run with privileged access. Which Kubernetes security mechanism should be applied?

A.Pod Security Standards
B.Network policies
C.ConfigMaps
D.Service accounts
AnswerA

Pod Security Standards define the privileged, baseline and restricted profiles enforced via pod security admission, blocking containers that request privileged mode. This directly satisfies the constraint that containers cannot run with privileged access, unlike RBAC, which governs API permissions rather than pod capabilities.

Why this answer

Pod Security Standards (PSS) define three profiles — Privileged, Baseline, and Restricted — that control whether pods can run with privileged access, host networking, hostPath volumes, and similar elevated capabilities. Enforcing the Restricted or Baseline profile via Pod Security Admission prevents containers from running privileged. This is the native Kubernetes mechanism for restricting pod-level privileges.

Exam trap

CV0-004 often tests the confusion between network-level controls (Network Policies) and workload-level privilege controls (Pod Security Standards) — candidates may pick Network Policies thinking they restrict container capabilities.

How to eliminate wrong answers

Option B is wrong because Network Policies control pod-to-pod network traffic (ingress/egress), not container privilege levels or security contexts. Option C is wrong because ConfigMaps store non-sensitive configuration data as key-value pairs and have no security enforcement role. Option D is wrong because Service Accounts provide identity for pods to authenticate to the Kubernetes API and external services, not runtime privilege restrictions.

109
MCQeasy

A startup is deploying a web application on AWS and wants to protect it from common Layer 7 attacks such as SQL injection and cross-site scripting. The application runs behind an Application Load Balancer, and the team wants a managed service that can be deployed quickly with minimal configuration. Which AWS service should they use?

A.AWS WAF
B.AWS Shield Advanced
C.Amazon GuardDuty
D.AWS Network Firewall
AnswerA

AWS WAF is a managed web application firewall that inspects HTTP(S) requests at Layer 7 and can block SQL injection and cross-site scripting using AWS Managed Rules. It integrates directly with Application Load Balancer, CloudFront, and API Gateway, and can be deployed quickly with preconfigured rule groups, matching the startup's need for minimal configuration.

Why this answer

AWS WAF is purpose-built to inspect HTTP(S) traffic and block Layer 7 attacks like SQL injection and XSS using managed rule groups. It integrates natively with Application Load Balancer and can be deployed in minutes, satisfying the startup's need for a managed, low-configuration solution. The other services address DDoS, threat detection, or network-layer filtering, not application payload protection.

Exam trap

The trap here is confusing Shield Advanced with WAF — Shield mitigates DDoS at the network layer, while WAF inspects application requests for injection and scripting attacks.

110
MCQeasy

Which of the following is a benefit of using a Web Application Firewall (WAF)?

A.Filtering malicious HTTP/HTTPS traffic to a web application
B.Encrypting data at rest in a database
C.Protecting against DDoS attacks at the network layer
D.Managing user identities and access
AnswerA

A WAF inspects inbound HTTP/HTTPS requests at layer 7, applying rule sets to block SQL injection, cross-site scripting and similar payloads before they reach the web server. This directly satisfies the stem's requirement to filter malicious web traffic rather than merely logging or rate-limiting it.

Why this answer

WAFs protect web applications from common attacks like SQL injection, cross-site scripting, and other OWASP Top 10 threats by filtering and monitoring HTTP/HTTPS traffic.

111
MCQeasy

A cloud architect is designing a network to protect a web application from common attacks such as SQL injection and cross-site scripting. Which cloud service should be used?

A.DDoS Protection
B.Network ACL
C.Web Application Firewall (WAF)
D.Security Group
AnswerC

A WAF inspects HTTP/S traffic at the application layer, filtering injection and scripting payloads via managed rule sets. Network firewalls and security groups operate at lower layers and cannot parse request content, so they miss these attacks. This directly satisfies the requirement to protect the web application.

Why this answer

A Web Application Firewall (WAF) is specifically designed to inspect HTTP/HTTPS traffic and block application-layer attacks such as SQL injection, cross-site scripting (XSS), and other OWASP Top 10 threats. It operates at Layer 7 and applies rule sets or signatures to web requests and responses. This makes it the correct cloud service for protecting a web application from these attacks.

Exam trap

CV0-004 often tests the confusion between Layer 3/4 controls (Security Groups, NACLs, DDoS Protection) and Layer 7 controls (WAF) — candidates pick Security Groups or NACLs because they sound like firewalls, but only a WAF inspects application payloads for SQLi/XSS.

How to eliminate wrong answers

Option A is wrong because DDoS Protection mitigates volumetric and protocol-level floods (Layer 3/4), not application-layer injection or scripting attacks. Option B is wrong because a Network ACL is a stateless Layer 3/4 packet filter based on IP, port, and protocol — it cannot inspect HTTP payloads for SQLi or XSS. Option D is wrong because a Security Group is a stateful Layer 3/4 virtual firewall for instances, filtering by IP/port/protocol but not inspecting application content.

112
MCQmedium

A security engineer is configuring a network security group (NSG) in Azure to allow inbound HTTPS traffic to a web server. The engineer creates an inbound rule allowing TCP port 443 from the Internet. What must be done to ensure the web server can respond to clients?

A.Create an outbound rule allowing all traffic to the Internet.
B.Create an inbound rule allowing TCP port 443 from the web server.
C.Create an outbound rule allowing TCP port 443 to the Internet.
D.No additional rule is needed because the NSG is stateful.
AnswerD

Network security groups are stateful, so return traffic for an allowed inbound connection is automatically permitted regardless of outbound rules. Because the inbound TCP 443 rule already establishes the flow, replies from the web server reach clients without any additional outbound rule.

Why this answer

NSGs are stateful; allowing inbound traffic automatically allows the corresponding outbound response traffic.

113
MCQmedium

A security engineer is configuring an AWS IAM policy for a new application. The policy must allow the application to read objects from a specific S3 bucket. Which IAM policy element determines whether the action is allowed or denied?

A.Effect
B.Action
C.Resource
D.Condition
AnswerA

The Effect element specifies whether a matching statement results in Allow or Deny, making it the axis that determines the policy outcome. With the action and resource already scoped to s3:GetObject on the named bucket, Effect supplies the explicit Allow the stem requires.

Why this answer

The Effect element in an IAM policy specifies whether the statement allows or denies access. It is a required element that can be set to 'Allow' or 'Deny'. In this case, to allow the application to read objects, the Effect must be 'Allow'.

Therefore, the Effect element determines whether the action is allowed or denied.

Exam trap

The trap is confusing the roles of the four elements; candidates might think Action or Resource determines allow/deny, but only Effect explicitly sets the permission outcome.

How to eliminate wrong answers

Option B is wrong because Action specifies the API operations (e.g., s3:GetObject) that the policy applies to, but it does not determine allow/deny by itself. Option C is wrong because Resource specifies the object or objects the policy applies to (e.g., a specific S3 bucket), but it does not determine allow/deny. Option D is wrong because Condition specifies circumstances under which the policy is in effect (e.g., IP range, MFA), but it does not determine allow/deny; it only refines when the statement applies.

114
MCQeasy

According to the shared responsibility model, which of the following is the cloud provider responsible for?

A.Operating system patching
B.Physical infrastructure security
C.Application code security
D.Identity and access management configuration
AnswerB

Under the shared responsibility model, the cloud provider owns security of the cloud: datacentre facilities, hardware, networking and physical access controls. The customer remains responsible for security in the cloud, covering guest OS patching, application configuration and identity management.

Why this answer

Under the shared responsibility model, the cloud provider is always responsible for the security OF the cloud — the physical facilities, hardware, network fabric, and hypervisor layer that underpin the service. Physical infrastructure security (data center access controls, hardware disposal, environmental controls) is entirely the provider's domain and cannot be delegated to the customer. Customers are responsible for security IN the cloud, which covers their data, configurations, and workloads.

Exam trap

The trap here is confusing 'security OF the cloud' (provider) with 'security IN the cloud' (customer) — candidates often assume the provider patches everything, but OS patching and IAM remain customer duties in most service models.

How to eliminate wrong answers

Option A is wrong because operating system patching is a customer responsibility in IaaS (and shared in PaaS), not the provider's — the customer owns guest OS patching for their instances. Option C is wrong because application code security always belongs to the customer, since the provider has no visibility into or control over the customer's application logic. Option D is wrong because identity and access management configuration is a customer responsibility — the customer defines users, roles, permissions, and MFA policies for their own tenant.

115
Multi-Selectmedium

A cloud security team is implementing the principle of least privilege for IAM roles. Which TWO actions are consistent with this principle?

Select 2 answers
A.Grant full administrative access to all users to simplify management
B.Regularly review and revoke unused permissions
C.Create custom roles with only the specific permissions needed for each job function
D.Use wildcard (*) permissions to allow all actions on a resource
E.Assign root user access to all developers
AnswersB, C

Regularly reviewing and revoking unused permissions enforces least privilege by continuously shrinking each IAM role's effective permissions. This satisfies the stem's constraint because stale, unused grants are removed rather than left accumulating, limiting the blast radius if credentials are compromised.

Why this answer

Option B is correct because regularly reviewing and revoking unused permissions enforces least privilege over time, eliminating accumulated or stale entitlements that could be exploited. Option C is correct because creating custom roles scoped to only the specific permissions each job function requires directly embodies least privilege, granting no more access than necessary. Option A is wrong because granting full administrative access to all users violates least privilege by massively over-provisioning rights.

Option D is wrong because wildcard (*) permissions allow all actions on a resource, which is the opposite of narrowly scoped access. Option E is wrong because assigning root user access to all developers grants the most privileged account to many people, directly contradicting least privilege.

Exam trap

CV0-004 often tests the difference between least privilege and convenience — candidates may pick 'full admin to simplify management' because it sounds operationally efficient, but it directly contradicts the principle.

116
MCQmedium

A security auditor is reviewing the IAM configuration for a cloud account. The auditor finds that a user has permissions to create and delete resources in all services. Which principle of security is being violated?

A.Need to know
B.Defense in depth
C.Least privilege
D.Separation of duties
AnswerC

Granting a user create and delete permissions across all services exceeds what their role requires, breaching least privilege, which limits rights to the minimum needed. The other principles address separation of duties, defence in depth and need to know, not excessive permission scope.

Why this answer

The principle of least privilege is violated because the user has permissions to create and delete resources in all services, which is far more than necessary for their role. Least privilege requires granting only the minimum permissions needed to perform a task.

Exam trap

CV0-004 often tests security principles, and candidates might confuse least privilege with separation of duties or need to know, especially when the scenario involves broad permissions.

How to eliminate wrong answers

Option A is wrong because 'need to know' is about information access, not resource permissions. Option B is wrong because 'defense in depth' is about layered security controls, not about excessive permissions. Option D is wrong because 'separation of duties' is about dividing tasks among different users to prevent fraud, but the issue here is excessive permissions for a single user.

117
MCQeasy

Which of the following is a key benefit of using a Cloud Access Security Broker (CASB)?

A.Automates resource provisioning
B.Provides DDoS protection
C.Manages encryption keys for on-premises data
D.Discovers and controls use of unauthorized cloud applications
AnswerD

A CASB provides shadow IT discovery, identifying cloud applications in use that fall outside sanctioned policy. It then enforces controls such as blocking or restricting those unsanctioned services, satisfying the requirement to both discover and control unauthorised cloud application usage.

Why this answer

CASBs provide visibility and control over SaaS applications, including shadow IT discovery.

118
Multi-Selectmedium

A cloud administrator is configuring a CASB (Cloud Access Security Broker) for SaaS applications. Which TWO capabilities should the administrator expect from the CASB? (Choose two.)

Select 2 answers
A.Discover and control shadow IT usage
B.Manage on-premises server patches
C.Apply data loss prevention (DLP) policies
D.Provide local DNS resolution
E.Replace the cloud provider's infrastructure
AnswersA, C

CASBs provide discovery of unsanctioned SaaS usage, identifying shadow IT across the organisation, then enforce granular controls such as blocking or restricting those applications. This visibility and control capability directly matches the stem's SaaS-focused CASB deployment.

Why this answer

Option A is correct because a core CASB function is discovery of shadow IT — the CASB uses API connectors, log analysis, and traffic inspection to identify unsanctioned SaaS usage and then apply control (block, coach, or allow) policies. Option C is correct because CASBs enforce data loss prevention policies on cloud traffic and data at rest, inspecting content for sensitive patterns (PII, PCI, credentials) and applying actions such as block, quarantine, or encryption via API or inline proxies. Options B, D, and E are incorrect: patch management of on-premises servers is a configuration management/endpoint tool function, local DNS resolution is provided by DNS servers (e.g., BIND, Windows DNS) rather than a CASB, and a CASB never replaces the cloud provider's infrastructure — it sits alongside SaaS/IaaS to provide visibility, compliance, threat protection, and data security.

Exam trap

CV0-004 often tests the misconception that a CASB is a network security appliance that provides infrastructure services like DNS or patching, when it is actually a policy enforcement point for cloud usage visibility and data protection.

119
Multi-Selectmedium

A cloud security team is hardening a Linux virtual machine that hosts a public-facing API in a public cloud. The team wants to reduce the attack surface at the operating system layer and detect unauthorized file changes. Which TWO measures should the team implement? (Choose two.)

Select 2 answers
A.Store the virtual machine's SSH host keys in a publicly readable object storage bucket for easy distribution to clients.
B.Grant the API service account full administrative privileges on the virtual machine to simplify troubleshooting and deployment.
C.Remove or disable unnecessary services, packages, and listening ports that the API does not require.
D.Enable a host-based intrusion detection system that monitors critical system files and alerts on unexpected modifications.
E.Disable the local firewall and rely solely on the cloud provider's security group rules for all traffic filtering.
AnswersC, D

Eliminating unneeded services, packages, and open ports directly shrinks the attack surface of the operating system, which is exactly the first goal. Every extra daemon is a potential entry point and patch burden, so removing them reduces exploitable vulnerabilities. This is a foundational hardening step that pairs well with integrity monitoring to cover both reduction and detection objectives.

Why this answer

Reducing the attack surface means removing unnecessary services, packages, and listening ports so fewer exploitable components remain on the host. Detecting unauthorized changes requires a host-based intrusion detection system that monitors file integrity and alerts on tampering. Together these cover both the reduction and detection goals, while the remaining options either expand privileges, weaken layered filtering, or expose trust material insecurely.

Exam trap

The trap here is treating cloud security group rules as a complete substitute for host-level hardening and monitoring.

120
MCQeasy

A cloud administrator needs to protect a web application from common attacks such as SQL injection and cross-site scripting (XSS). Which cloud service should be implemented?

A.DDoS protection service
B.Network ACL
C.Security group
D.Web Application Firewall (WAF)
AnswerD

A Web Application Firewall inspects HTTP/S requests at layer 7 and blocks signatures matching SQL injection and XSS payloads before they reach the application. Network firewalls and load balancers operate at lower layers and cannot parse request content to detect these attacks.

Why this answer

A Web Application Firewall (WAF) is specifically designed to filter and monitor HTTP traffic, blocking common web exploits like SQL injection and XSS. Cloud providers offer WAF services (e.g., AWS WAF, Azure WAF, Cloud Armor).

121
Multi-Selectmedium

A cloud administrator is configuring an Azure environment for a healthcare application that must comply with HIPAA. Which TWO configurations are required to meet HIPAA security and privacy rules? (Choose two.)

Select 2 answers
A.Implement audit logging for access to ePHI
B.Configure network security groups to allow only HTTPS traffic
C.Enable multi-factor authentication for all administrative accounts
D.Configure automatic patching for all virtual machines
E.Enable encryption at rest for all storage accounts containing ePHI
AnswersA, E

HIPAA requires audit controls to record access to ePHI.

Why this answer

Audit logging for access to ePHI is required by HIPAA to track who accessed, modified, or deleted protected health information. In Azure, this is implemented through Azure Monitor and Log Analytics, which capture detailed audit trails for storage accounts, databases, and applications. Without audit logs, the organization cannot demonstrate compliance with the HIPAA Security Rule's requirement for activity monitoring and accountability.

Exam trap

The trap here is that candidates often confuse 'best practices' (like MFA and automatic patching) with 'required configurations' under HIPAA, leading them to select options that are recommended but not explicitly mandated by the Security Rule.

← PreviousPage 2 of 2 · 121 questions total

Ready to test yourself?

Try a timed practice session using only Security questions.