CloudSec-Pro Practice Question: Cloud Security Fundamentals And Shared Responsibility
You are analyzing a Prisma Cloud deployment to enforce compliance. You discover that a developer has created a public S3 bucket containing sensitive data. Which principle of the cloud security model is being violated?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The customer's responsibility for resource configuration and data security
The customer is responsible for 'Security in the Cloud', which includes misconfiguration management and data exposure risks, even if the platform provides the security tools.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The customer's responsibility for resource configuration and data security
Why this is correct
Securing the configuration of cloud resources is a core customer responsibility.
- ✗
The shared responsibility for data center perimeter security
Why it's wrong here
This is irrelevant to the S3 bucket configuration issue.
- ✗
The provider's responsibility for identity and access management
Why it's wrong here
IAM configuration is a customer responsibility.
- ✗
The provider's responsibility for infrastructure availability
Why it's wrong here
Availability is a provider responsibility, not security policy enforcement.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
About these practice questions
This CloudSec-Pro question is part of Courseiva's 203-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official Palo Alto Networks exam blueprint
This CloudSec-Pro practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CloudSec-Pro exam.