Courseiva

CloudSec-Pro · domain

Cloud Security Fundamentals And Shared Responsibility

Practise Certified Cloud Security Professional (CloudSec-Pro) Cloud Security Fundamentals And Shared Responsibility practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

40 questions14 easy14 medium12 hard

Focused practice

Practice Cloud Security Fundamentals And Shared Responsibility questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Cloud Security Fundamentals And Shared Responsibility

Cloud concepts questions usually test the service model (IaaS/PaaS/SaaS) and deployment model (public/private/hybrid/community) appropriate for a given scenario.

IaaS, PaaS and SaaS responsibilities and examples.

Public, private, hybrid and community cloud deployment models.

On-premises vs cloud trade-offs: cost, control, scalability.

How cloud connectivity options (VPN, Direct Connect, ExpressRoute) work.

Watch out for

Common Cloud Security Fundamentals And Shared Responsibility exam traps

  • IaaS gives you infrastructure control; SaaS gives you only the application.
  • Hybrid cloud combines on-premises and public cloud — not two public clouds.
  • Cloud does not automatically mean cheaper or more secure.
  • Management responsibility shifts with each service model (IaaSPaaSSaaS).

Question index

All Cloud Security Fundamentals And Shared Responsibility questions (40)

Click any question to see the full explanation, or start a practice session above.

1

Which TWO of the following are primary security benefits of using cloud-native security tools? (Choose two)

Medium
2

Which type of encryption should be used to protect data at rest in a cloud storage bucket?

Easy
3

Which THREE of the following are critical components of a comprehensive Cloud Security strategy? (Choose three)

Hard
4

Which THREE of the following are required to maintain a secure cloud-native environment? (Choose three)

Medium
5

When using Azure Key Vault to store secrets, which entity holds the responsibility for the protection of the underlying hardware security module (HSM)?

Hard
6

You are configuring a security group in AWS. What is the default behavior for inbound traffic?

Medium
7

In the context of 'Shared Responsibility', what does the customer typically manage in a SaaS (Software as a Service) offering?

Medium
8

What is the primary function of a Cloud Security Posture Management (CSPM) tool?

Hard
9

When implementing a 'Zero Trust' architecture in cloud, which component is most critical for verifying requests?

Hard
10

Which of the following is a benefit of using 'Identity and Access Management' (IAM) groups?

Easy
11

You are deploying a workload on Azure and need to ensure that the underlying hardware maintenance is handled by Microsoft. Which aspect of the Shared Responsibility Model does this represent?

Medium
12

Which service should you use to monitor for potential unauthorized API calls in your AWS account?

Medium
13

You are auditing a cloud environment where a developer has created an S3 bucket with public read access. Under the AWS Shared Responsibility Model, who is responsible for configuring the bucket policy to restrict this access?

Easy
14

In a Google Cloud environment using Cloud SQL, which task remains the customer's responsibility?

Hard
15

Which TWO of the following are common risks associated with misconfigured cloud storage buckets? (Choose two)

Medium
16

Which THREE of the following are pillars of a Zero Trust approach? (Choose three)

Hard
17

You are analyzing a security risk in a multi-cloud environment. What is the most significant challenge regarding the Shared Responsibility Model?

Medium
18

Which TWO of the following are common cloud-native security practices? (Choose two)

Easy
19

When securing a containerized application, where should you place the primary focus for security?

Medium
20

A security administrator is evaluating the shared responsibility model for an AWS deployment. Which task remains the sole responsibility of the customer when using Amazon RDS?

Easy
21

When using 'Infrastructure as Code' (IaC), what is a key security risk if templates are shared publicly?

Medium
22

Which THREE of the following are examples of cloud-native security concepts?

Easy
23

Which cloud security concept allows for the rapid restoration of services after a security incident?

Easy
24

A security team is implementing 'Shift Left' security. What is the fundamental shift in responsibility for the development team?

Medium
25

Which TWO of the following are examples of customer responsibilities in the AWS Shared Responsibility Model? (Choose two)

Easy
26

What is the primary goal of the 'Principle of Least Privilege' in a cloud environment?

Easy
27

When evaluating Cloud-Native Security Platforms (CNSP), which area is primarily the responsibility of the cloud provider?

Easy
28

Which of the following is a core characteristic of cloud-native security?

Easy
29

In the context of AWS, which tool provides visibility into compliance and configuration drift?

Medium
30

Which TWO of the following are effective ways to secure access to your cloud management console? (Choose two)

Easy
31

You are analyzing a Prisma Cloud deployment to enforce compliance. You discover that a developer has created a public S3 bucket containing sensitive data. Which principle of the cloud security model is being violated?

Hard
32

You are auditing an Azure environment. You need to ensure that the security of your guest operating systems is maintained. Under the shared responsibility model, what is the customer's primary responsibility for IaaS Virtual Machines?

Medium
33

In AWS, what is the best way to grant a temporary role to an external third-party auditor without creating permanent IAM users?

Hard
34

Which of the following is a critical step when performing a 'Cloud-Native' threat model?

Hard
35

What is the primary function of 'Multi-Factor Authentication' (MFA) in a cloud environment?

Easy
36

Which THREE of the following tasks are exclusively the responsibility of the cloud provider in a SaaS model?

Hard
37

A security architect is designing a multi-cloud strategy on GCP. Which component must the customer configure to ensure data protection within the shared responsibility model for Google Cloud Storage?

Medium
38

When configuring 'VPC Service Controls' in GCP, what is the main security benefit?

Hard
39

A company is migrating a legacy application to a containerized environment using Amazon EKS. Under the shared responsibility model, which action must the customer perform to secure the control plane?

Hard
40

In GCP, what is the primary purpose of 'Organization Policy Service'?

Easy

Frequently asked questions

What does the Cloud Security Fundamentals And Shared Responsibility domain cover on the CloudSec-Pro exam?
Cloud concepts questions usually test the service model (IaaS/PaaS/SaaS) and deployment model (public/private/hybrid/community) appropriate for a given scenario.
How many questions are in this domain?
This page lists all 40 Cloud Security Fundamentals And Shared Responsibility questions in the CloudSec-Pro question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Cloud Security Fundamentals And Shared Responsibility questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
Certified Cloud Security Professional (CloudSec-Pro) Cloud Security Fundamentals And Shared Responsibility Practice Questions