312-39 · domain
SOC For Cloud Environments
Practise Certified SOC Analyst (312-39) SOC For Cloud Environments practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice SOC For Cloud Environments questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about SOC For Cloud Environments
Watch out for
Common SOC For Cloud Environments exam traps
Question index
All SOC For Cloud Environments questions (16)
Click any question to see the full explanation, or start a practice session above.
Which THREE of the following are benefits of using a SIEM integrated with Cloud native logs?
Hard2Your organization uses Google Cloud Platform. You need to identify which service provides VPC flow logs to monitor network traffic patterns between instances. Which service is used?
Easy3Which Azure feature allows you to automatically enforce security settings on your resources to prevent unauthorized changes?
Easy4You notice an unusual amount of outbound traffic from an Azure VM to a known malicious IP. What is the most effective way to block this traffic immediately at the network level?
Medium5A SOC analyst is using GCP and sees an alert regarding 'exfiltration of data' from a Cloud Storage bucket. Which tool should be analyzed to identify the specific file names accessed during the event?
Hard6You are configuring AWS GuardDuty to improve threat detection. You need to ensure it monitors for unusual S3 bucket access. Which data source must be enabled for this?
Medium7You are investigating an unauthorized login to an AWS IAM role. You need to determine the specific API call that was made and the source IP address. Which AWS service should you query?
Medium8You are performing a cloud-native incident response in AWS. You need to isolate a compromised EC2 instance without deleting the volume. What is the standard process?
Medium9Which TWO settings should you prioritize when configuring AWS CloudTrail for a robust security audit trail?
Medium10Which THREE of the following are common indicators of a cloud account compromise that should be monitored in your SOC?
Hard11Which TWO actions should be taken when you find a rogue VM in your GCP environment?
Medium12In Azure, you suspect a compromised VM is being used for cryptocurrency mining. You want to see process-level execution details on that VM. Which tool should you use?
Hard13Which TWO of the following are primary components of a cloud-native incident response plan?
Medium14You are managing security for GCP. You need to detect if a service account has been created with excessive permissions. Which Google Cloud tool provides this insight?
Medium15Which AWS service is specifically designed to act as a centralized dashboard for finding security-related misconfigurations across your entire organization?
Easy16In Azure, you have detected a suspicious VM login. You need to investigate the sign-in patterns, including geographic location and device risk level. Where in the Azure portal should you look?
HardOther domains
All 312-39 exam domains
Frequently asked questions
- What does the SOC For Cloud Environments domain cover on the 312-39 exam?
- Cloud concepts questions usually test the service model (IaaS/PaaS/SaaS) and deployment model (public/private/hybrid/community) appropriate for a given scenario.
- How many questions are in this domain?
- This page lists all 16 SOC For Cloud Environments questions in the 312-39 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only SOC For Cloud Environments questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.