Courseiva

CCNA Cloud Platform and Infrastructure Security Questions

75 of 111 questions · Page 1/2 · Cloud Platform and Infrastructure Security · Answers revealed

1
MCQhard

A company has multiple VPCs in different cloud accounts that need to communicate with each other. They also need to enforce centralized security policies and simplify network management. Which cloud networking service should they use to create a hub-and-spoke topology?

A.Virtual network peering
B.Cloud transit gateway
C.Private link service
D.Virtual network endpoint
AnswerB

A cloud transit gateway acts as a regional hub, peering each VPC through a single attachment rather than building a full mesh of pairwise connections. This satisfies the centralised policy enforcement and simplified management constraints, since security rules and routing are configured once at the hub across all accounts.

Why this answer

A cloud transit gateway allows you to connect multiple VPCs and on-premises networks through a central hub, simplifying management and enabling centralized security policies. Virtual network peering is point-to-point and does not scale well for many VPCs.

2
MCQmedium

A cloud security engineer is concerned about VM escape attacks in a multi-tenant environment. Which of the following is the most effective mitigation strategy?

A.Regularly patching and updating the hypervisor
B.Using host-based intrusion detection on each VM
C.Implementing network segmentation between VMs
D.Enforcing strong passwords on guest OS accounts
AnswerA

VM escape exploits abuse hypervisor vulnerabilities, so regularly patching and updating the hypervisor removes the flaws an attacker needs to break out of a guest. This directly mitigates the escape vector in a multi-tenant environment where one flaw could expose co-resident tenants.

Why this answer

VM escape attacks exploit hypervisor vulnerabilities. The primary defense is to keep the hypervisor patched and hardened, as other controls like IDS/IPS or guest OS hardening do not directly prevent escape.

3
Multi-Selectmedium

A company is deploying a multi-tier application on AWS. They need to protect the application layer from common web attacks and also restrict traffic between tiers. Which TWO network security controls should they use?

Select 2 answers
A.PrivateLink for database access
B.AWS WAF integrated with Application Load Balancer
C.Security groups between application tiers
D.VPC peering with all VPCs
E.Network ACLs for each subnet
AnswersB, C

AWS WAF attached to an Application Load Balancer inspects HTTP/HTTPS requests at layer 7, blocking SQL injection, cross-site scripting and similar OWASP threats. This satisfies the requirement to protect the application layer from common web attacks.

Why this answer

Option B (AWS WAF integrated with Application Load Balancer) is correct because AWS WAF inspects HTTP/HTTPS requests at Layer 7 and can block common web exploits such as SQL injection and cross-site scripting using managed rule groups attached to an ALB, directly satisfying the requirement to protect the application layer. Option C (Security groups between application tiers) is correct because security groups are stateful, instance-level virtual firewalls whose inbound rules can reference other security groups, allowing precise tier-to-tier traffic restriction (for example, permitting only the app tier's SG to reach the database tier on port 3306). Option A is not appropriate here because PrivateLink provides private connectivity to services and endpoints, not application-layer attack filtering or inter-tier traffic control.

Option D is wrong because VPC peering only connects networks for routing and does not filter or restrict traffic between application tiers. Option E is less suitable because network ACLs are stateless, subnet-level filters that cannot reference security groups or enforce granular per-tier application rules as cleanly as security groups.

4
MCQhard

A cloud security engineer is configuring network security for a multi-tier application in AWS. The web servers must be accessible from the internet on port 443, the application servers should only receive traffic from the web servers, and the database servers should only accept traffic from the application servers on port 3306. Which combination of security controls should be used?

A.Security groups with source referencing the web server security group for app tier, and app server security group for DB tier
B.NACLs on each subnet with rules referencing source IP ranges
C.A single NACL applied to all subnets with layer 7 filtering
D.Route tables with deny rules to restrict inter-subnet traffic
AnswerA

Security groups support source referencing, so the app tier's inbound rule names the web server security group and the database tier's names the app server security group. This enforces the tiered traffic flow on port 3306 without hard-coded CIDRs, satisfying the stem's constraints.

Why this answer

In AWS, security groups are stateful virtual firewalls that can reference other security groups as sources. For the web tier, allow inbound 443 from 0.0.0.0/0. For the app tier, allow inbound from the web server security group.

For the DB tier, allow inbound on 3306 from the app server security group. This creates a least-privilege, layered defense without hardcoding IP addresses.

Exam trap

CCSP often tests the difference between security groups (stateful, instance-level, allow rules only) and NACLs (stateless, subnet-level, allow/deny rules), and candidates may incorrectly choose NACLs for dynamic, least-privilege control.

How to eliminate wrong answers

Option B is wrong because NACLs are stateless and operate at the subnet level; referencing source IP ranges is less dynamic and does not automatically adapt to autoscaling web servers, increasing management overhead and risk of misconfiguration. Option C is wrong because a single NACL with layer 7 filtering is not possible—NACLs operate at layers 3 and 4 and cannot inspect application-layer data. Option D is wrong because route tables control routing, not security; they do not have deny rules for inter-subnet traffic in the way described, and security is not their purpose.

5
MCQmedium

A cloud security team is implementing VPC peering between two VPCs in the same region. Which statement about VPC peering is correct?

A.VPC peering requires VPN gateways to establish connectivity
B.VPC peering enables private IP connectivity across VPCs without internet
C.VPC peering automatically encrypts all traffic between VPCs
D.VPC peering supports transitive routing through intermediate VPCs
AnswerB

VPC peering establishes a direct routing relationship between two VPCs using their private IPv4 or IPv6 addresses, so instances communicate over the cloud provider's internal backbone. Traffic never traverses the public internet, satisfying the private connectivity requirement without gateways or VPNs.

Why this answer

VPC peering creates a direct, private network route between two VPCs using their private IPv4 or IPv6 CIDR blocks, so instances communicate as if on the same network without traversing the public internet, VPN, or a NAT device. Traffic stays on the cloud provider's backbone, which is why it is considered private connectivity. This is the defining characteristic of VPC peering and the reason it is used for cross-VPC application tiers, shared services, and multi-account architectures.

Exam trap

The trap here is conflating 'private connectivity' with 'encrypted connectivity' — candidates assume private automatically means encrypted, but VPC peering provides routing isolation, not cryptographic protection.

How to eliminate wrong answers

Option A is wrong because VPC peering does not require VPN gateways — it is a native routing relationship between VPCs, not an IPsec tunnel; VPN gateways are used for site-to-site or client VPN connectivity. Option C is wrong because VPC peering does not automatically encrypt traffic; it provides private routing, and encryption must be added separately (e.g., TLS at the application layer) if required. Option D is wrong because VPC peering is explicitly non-transitive — if VPC A peers with B and B peers with C, A cannot reach C through B; a direct peering or a transit gateway is needed.

6
MCQmedium

A cloud security architect is designing the network segmentation for a three-tier web application hosted in a single Amazon VPC. The database tier must accept connections only from the application tier, and the application tier must accept connections only from the web tier. The architect wants the enforcement to be stateful, evaluated per elastic network interface, and independent of subnet CIDR ranges so that instances can be replaced without rewriting rules. Which control should the architect use to enforce this segmentation?

A.A VPC peering connection between the three tier subnets with route table entries restricting traffic
B.AWS PrivateLink endpoints published by each tier and consumed by the tier above it
C.Security groups attached to each tier's instances, referencing other security groups as sources
D.Network ACLs on each subnet, with rules that allow only the CIDR range of the adjacent tier's subnet
AnswerC

Security groups are stateful, attach to elastic network interfaces, and support referencing another security group as a source. This lets the database tier accept traffic only from the application tier's group, and the application tier only from the web tier's group, without hardcoding subnet CIDR ranges. Replacement instances that join the same group inherit the rules automatically, which matches the architect's requirements exactly.

Why this answer

Security groups provide stateful, interface-level filtering and allow other security groups to be referenced as sources, which decouples the rules from subnet addressing. That combination satisfies the stateful, per-interface, CIDR-independent requirement and survives instance replacement. Subnet-level ACLs, route tables, and PrivateLink endpoints do not deliver group-based, stateful enforcement within a single VPC.

Exam trap

The trap here is assuming that network ACLs provide the same stateful, group-referenced filtering as security groups, when ACLs are stateless and CIDR-based.

7
MCQmedium

Which container image security practice is most effective at reducing the attack surface by removing unnecessary components and lowering the number of CVEs?

A.Using the :latest tag for base images
B.Adding security agents inside the image
C.Using distroless base images
D.Scanning images only at build time
AnswerC

Distroless images contain only the application and its runtime dependencies, omitting package managers, shells and OS utilities. Removing these unnecessary components shrinks the attack surface and reduces the CVE count, directly satisfying the stem's constraint.

Why this answer

Distroless images contain only the application and its runtime dependencies, minimizing the attack surface.

8
MCQhard

A cloud security engineer is responsible for securing a serverless application built on AWS Lambda. The application processes sensitive customer data and writes results to an Amazon S3 bucket. The engineer must ensure that the Lambda function has only the permissions it needs to write to that specific bucket, and that the credentials are not hardcoded. Which approach should the engineer take?

A.Use an IAM user with an inline policy for S3 access and configure the Lambda function to use those credentials via the AWS SDK.
B.Embed the access keys in the Lambda function's environment variables.
C.Create an IAM role with a policy granting s3:PutObject to the specific bucket and attach it to the Lambda function.
D.Store IAM user access keys in AWS Secrets Manager and retrieve them in the Lambda function code.
AnswerC

This approach follows the principle of least privilege by granting only the necessary permission to the specific bucket. The IAM role is assumed by the Lambda function at runtime, and AWS automatically rotates the temporary credentials. This eliminates hardcoded credentials and ensures secure access. It is the recommended best practice for Lambda functions.

Why this answer

The best practice for granting permissions to AWS Lambda is to use an IAM role with a narrowly scoped policy. The role provides temporary credentials that are automatically rotated, and the policy grants only the required s3:PutObject permission to the specific bucket. This adheres to least privilege and eliminates the need for hardcoded or stored long-term credentials.

Other options involve long-term credentials or insecure storage, which are not recommended.

Exam trap

The trap here is thinking that storing keys in Secrets Manager is secure enough, but it still uses long-term credentials instead of temporary role-based access.

9
MCQmedium

A cloud security architect is designing a multi-tenant SaaS platform hosted on AWS. The platform must ensure that each tenant's data is cryptographically isolated so that even a compromised application instance in one tenant's environment cannot decrypt another tenant's data. The architect wants to use AWS Key Management Service (KMS) to manage encryption keys. Which approach BEST meets this requirement?

A.Use AWS KMS with a single customer managed key, but enable automatic key rotation every 90 days and require all tenants to use the same key alias for encryption and decryption.
B.Use a single AWS KMS customer managed key with a key policy that grants decrypt permissions to all tenant application roles, and rely on application-level tenant ID checks before decryption.
C.Create a separate AWS KMS customer managed key per tenant, with a key policy that grants decrypt permission only to that tenant's application role, and store the tenant's data encrypted under its own key.
D.Store all tenant data in a single Amazon S3 bucket encrypted with SSE-S3, and use S3 bucket policies to restrict each tenant's application role to its own prefix.
AnswerC

Per-tenant KMS keys with scoped key policies enforce cryptographic isolation at the key-management layer. Even if an application instance is compromised, its IAM role only has decrypt permission on its own tenant's key, so it cannot decrypt other tenants' ciphertext. This directly satisfies the requirement.

Why this answer

Cryptographic isolation in a multi-tenant cloud environment requires that each tenant's data be protected by a distinct key whose usage is governed by least-privilege policies. Per-tenant AWS KMS customer managed keys with narrowly scoped key policies ensure that a compromised application instance can only decrypt its own tenant's data. Shared keys, even with rotation or application-level checks, do not prevent cross-tenant decryption if credentials are compromised.

Exam trap

The trap here is assuming that application-level tenant ID checks or a shared KMS key with rotation provide sufficient isolation, when true cryptographic isolation requires distinct keys with scoped permissions per tenant.

10
MCQeasy

Which API Gateway security feature limits the number of requests from a client to prevent abuse or DoS attacks?

A.Rate limiting
B.JWT validation
C.WAF integration
D.Mutual TLS
AnswerA

Rate limiting caps how many requests a client may issue per time window, throttling abusive bursts before they exhaust backend capacity. This directly satisfies the stem's constraint of preventing abuse or denial-of-service attacks, unlike authentication or encryption features that address identity and confidentiality instead.

Why this answer

Rate limiting (also called throttling) caps the number of requests a client can make within a defined time window, protecting backend services from abuse, brute-force attempts, and denial-of-service floods. API gateways implement this with token bucket or leaky bucket algorithms, returning HTTP 429 Too Many Requests when the limit is exceeded. It is the primary control for request-volume abuse.

Exam trap

The trap is that all four options are legitimate API security features, so candidates must match the specific control to the specific threat — volume abuse maps to rate limiting, not authentication or content inspection.

How to eliminate wrong answers

Option B is wrong because JWT validation verifies the integrity and claims of a token to authenticate and authorise a caller — it does not limit request volume, and a valid token can still be used for a flood. Option C is wrong because WAF integration inspects HTTP payloads for attack signatures such as SQL injection or XSS; it filters malicious content, not request frequency. Option D is wrong because mutual TLS authenticates both client and server via certificates, providing strong identity assurance but no volume control.

11
Multi-Selecthard

A Kubernetes cluster is being hardened. Which THREE measures should be implemented to restrict container capabilities and reduce the risk of privilege escalation? (Select three.)

Select 3 answers
A.Enabling privileged mode for containers that need host access
B.Running containers as root
C.Running containers as a non-root user
D.Applying AppArmor or SELinux profiles
E.Dropping all Linux capabilities and adding only required ones
AnswersC, D, E

Running containers as a non-root user removes UID 0 inside the container, so a breakout or exploited process lacks root privileges on the host mount namespace. This directly reduces privilege-escalation risk, satisfying the hardening requirement alongside capability dropping and mandatory access controls.

Why this answer

Option C is correct because running containers as a non-root user (e.g., via securityContext.runAsNonRoot: true or a USER directive in the Dockerfile) prevents processes inside the container from having UID 0, which is the primary enabler of privilege-escalation exploits and container-escape techniques. Option D is correct because AppArmor or SELinux profiles enforce mandatory access control that confines container processes to a limited set of files, paths, and operations, blocking actions that even a compromised process could otherwise attempt. Option E is correct because dropping all Linux capabilities and adding back only those explicitly required (e.g., using cap-drop: ALL with a minimal cap-add list) removes dangerous privileges such as CAP_SYS_ADMIN, CAP_NET_RAW, and CAP_SYS_PTRACE that are commonly abused for privilege escalation.

Option A is incorrect because privileged mode grants the container nearly all host capabilities and device access, dramatically increasing the attack surface rather than restricting it. Option B is incorrect because running containers as root gives the process full UID 0 privileges inside the container, which is exactly the risk the hardening measures are meant to eliminate.

12
MCQeasy

Which of the following is the primary security risk associated with VM escape in a cloud environment?

A.Performance degradation of the VM
B.Loss of network connectivity
C.Data corruption within the VM
D.Unauthorized access to other tenants' VMs and the hypervisor
AnswerD

VM escape exploits a hypervisor or virtualisation flaw so code inside a guest breaks isolation and executes at the hypervisor layer. From there an attacker reads or controls other tenants' VMs on the same host, defeating multi-tenancy separation.

Why this answer

VM escape occurs when an attacker breaks out of the guest VM's isolation boundary and gains access to the hypervisor or other tenants' VMs. The primary security risk is therefore unauthorized access to other tenants' workloads and the hypervisor itself, which can lead to full compromise of the multi-tenant host. This breaks the fundamental isolation guarantee that cloud providers rely on.

Exam trap

The trap is selecting a performance or availability symptom — candidates must recognize that VM escape is fundamentally a confidentiality and isolation breach affecting other tenants and the hypervisor, not a local VM issue.

How to eliminate wrong answers

Option A is wrong because performance degradation is an availability concern, not the security consequence of escaping the isolation boundary; a VM escape is about confidentiality and integrity of other tenants. Option B is wrong because loss of network connectivity is a functional disruption, not the core security risk of hypervisor breakout. Option C is wrong because data corruption within the same VM is contained to that tenant and does not represent the cross-tenant or hypervisor-level compromise that defines VM escape.

13
MCQhard

A financial services firm runs a multi-tenant SaaS platform on AWS. A penetration test reveals that a compromised container on one tenant's node was able to read environment variables belonging to another tenant's pods scheduled on the same node. The platform uses Kubernetes with default settings, and pods are not configured with any security context. Which control most directly addresses this isolation failure?

A.Configure pod security contexts to run containers as non-root with readOnlyRootFilesystem and drop all Linux capabilities.
B.Encrypt all Kubernetes Secrets at rest using a KMS provider and rotate the encryption keys quarterly.
C.Enable Kubernetes Network Policies that deny all ingress and egress by default between namespaces.
D.Deploy each tenant's workloads using a dedicated container runtime sandbox such as gVisor or Kata Containers, or enforce pod-level isolation with user namespaces and separate runtime classes.
AnswerD

The leak occurred because containers on the same node share kernel and, in some configurations, process namespaces that allow visibility into sibling workloads. Stronger isolation boundaries such as gVisor, Kata Containers, or user namespaces with distinct runtime classes prevent one tenant's container from observing another's process environment. This directly closes the cross-tenant visibility path observed by the penetration test.

Why this answer

When containers share a node without strong isolation, one workload can sometimes observe another's process environment or runtime metadata. Enforcing dedicated sandboxes such as gVisor or Kata Containers, or isolating with user namespaces and distinct runtime classes, creates a hard boundary between tenants. This is the control that directly addresses the cross-tenant environment variable exposure described.

Exam trap

The trap here is assuming that pod-level hardening or network policies solve a node-level namespace isolation problem; those controls harden a single workload but do not separate tenants sharing a kernel.

14
MCQeasy

Which hypervisor type is most commonly deployed in production cloud data centers to host multiple tenant virtual machines?

A.Type 1 bare-metal hypervisor like VMware ESXi
B.Container runtime like Docker
C.Para-virtualization interface
D.Type 2 hosted hypervisor like VirtualBox
AnswerA

Type 1 hypervisors such as VMware ESXi run directly on hardware and are the standard production platform in cloud data centres, hosting many tenant VMs per physical host. Type 2 hypervisors run atop a host OS and are unsuitable for that scale and isolation.

Why this answer

Type 1 (bare-metal) hypervisors run directly on hardware and are used in cloud environments for better performance and isolation.

15
Multi-Selectmedium

A cloud security team is deploying a web application with an API Gateway. Which TWO mechanisms should be implemented to protect against API abuse and unauthorized access?

Select 2 answers
A.Rate limiting
B.TLS enforcement
C.Resource tagging
D.VPC peering
E.Authentication (e.g., JWT validation)
AnswersA, E

Rate limiting caps request volume per client or API key, throttling brute-force attempts, credential stuffing and volumetric abuse before they reach backend services. It directly addresses the API abuse constraint by bounding how many calls an attacker can issue.

Why this answer

Rate limiting (A) is correct because it throttles the number of requests a client can make in a given time window, directly mitigating API abuse such as brute-force attempts, credential stuffing, and denial-of-service floods that would otherwise overwhelm the gateway and backend. Authentication with JWT validation (E) is correct because it verifies the identity and integrity of the caller by validating the token's signature, issuer, audience, and expiry before granting access, thereby preventing unauthorized access to protected API routes. TLS enforcement (B) only encrypts data in transit and does not by itself stop abuse or authenticate API clients, so it does not satisfy the requirement.

Resource tagging (C) is a metadata and governance mechanism for cost allocation and organization, not a runtime access control. VPC peering (D) provides private network connectivity between VPCs but does not protect an internet-facing API Gateway against abuse or unauthorized callers.

Exam trap

The trap here is selecting TLS enforcement as a security control for API abuse, confusing confidentiality with availability and access control.

16
MCQeasy

A security architect is designing a multi-tenant cloud environment. Which type of hypervisor provides the strongest isolation for tenant virtual machines by running directly on the hardware without a host operating system?

A.Type 1 hypervisor
B.Type 2 hypervisor
C.Virtual machine monitor in user space
D.Container runtime
AnswerA

A Type 1 hypervisor runs directly on bare-metal hardware without an underlying host OS, eliminating the host kernel as a shared attack surface and providing stronger isolation between tenant virtual machines than hosted Type 2 hypervisors.

Why this answer

A Type 1 hypervisor runs directly on the hardware without a host operating system, providing stronger isolation for tenant virtual machines. This bare-metal architecture reduces the attack surface and prevents tenant VMs from interfering with each other through a host OS. Therefore, it is the correct answer for the strongest isolation in a multi-tenant cloud environment.

Exam trap

The trap is confusing Type 1 and Type 2 hypervisors, or assuming containers provide equivalent isolation; candidates must remember that Type 1 runs on bare metal and offers the strongest isolation.

How to eliminate wrong answers

Option B is wrong because a Type 2 hypervisor runs on top of a host operating system, which introduces additional overhead and potential vulnerabilities, making isolation weaker. Option C is wrong because a virtual machine monitor in user space is essentially a Type 2 hypervisor, which does not provide the same level of isolation as Type 1. Option D is wrong because a container runtime shares the host OS kernel, providing less isolation than a Type 1 hypervisor, as containers are not fully isolated VMs.

17
MCQmedium

In a Kubernetes cluster, which resource should be used to restrict network traffic between pods based on source and destination labels?

A.Pod Security Admission
B.Network Policies
C.Secrets management with Vault
D.Role-Based Access Control (RBAC)
AnswerB

Network Policies are Kubernetes objects that select pods by label and define permitted ingress and egress rules, enforced by the CNI plugin. They satisfy the stem's label-based restriction on inter-pod traffic, unlike security groups or firewall rules that operate outside pod identity.

Why this answer

Network policies in Kubernetes act as a firewall for pods, allowing or denying traffic based on selectors.

18
Multi-Selectmedium

A cloud security team is evaluating controls for protecting data in a PaaS database service. The database must support tenant isolation, and the team wants to prevent one tenant's queries from accessing another tenant's rows. Which TWO controls BEST achieve row-level tenant isolation? (Choose two.)

Select 2 answers
A.Enable database auditing and alert on queries that return more than a threshold number of rows.
B.Use separate database schemas per tenant with distinct database roles and grant only schema-scoped privileges.
C.Implement row-level security policies in the database engine that filter rows based on the authenticated tenant identity.
D.Enable transparent data encryption on the database so that rows are encrypted at rest with a service-managed key.
E.Configure the application to append a tenant_id filter to every generated SQL statement.
AnswersB, C

Schema-per-tenant with role-scoped grants limits each tenant's session to its own schema, providing a strong boundary. Combined with row-level policies or as an alternative, it prevents cross-tenant access at the privilege layer and reduces the blast radius of a compromised application credential.

Why this answer

Row-level security policies and schema-per-tenant with role-scoped grants both enforce isolation inside the database engine, so cross-tenant access is blocked regardless of application behavior. TDE, application-side filtering, and auditing do not prevent a query from reaching another tenant's rows, making them insufficient as primary isolation controls.

Exam trap

The trap here is treating encryption at rest or application-side filtering as tenant isolation, when only database-enforced controls such as row-level security or schema-scoped privileges actually prevent cross-tenant row access.

19
MCQmedium

An organization exposes an API via Amazon API Gateway. They need to protect against common web exploits like SQL injection and cross-site scripting. Which integration should they enable?

A.IAM policies
B.Security groups on the API Gateway
C.AWS WAF
D.Network ACLs on the VPC
AnswerC

AWS WAF attaches to API Gateway stages and inspects HTTP requests against managed or custom rules, blocking SQL injection and cross-site scripting payloads before they reach the backend. This satisfies the requirement to protect the exposed API against common web exploits.

Why this answer

AWS WAF is a web application firewall that integrates with Amazon API Gateway to protect against common web exploits like SQL injection and cross-site scripting. It inspects incoming HTTP/HTTPS requests and applies rules to block malicious traffic. Enabling AWS WAF on the API Gateway stage provides the required protection.

Exam trap

CCSP often tests the layer at which security controls operate; candidates may choose network-layer controls (security groups, NACLs) for application-layer threats, confusing the OSI model layers.

How to eliminate wrong answers

Option A is wrong because IAM policies control authentication and authorization for AWS resources, not web exploit filtering; they do not inspect request payloads for SQLi or XSS. Option B is wrong because security groups act at the network layer (IP/port level) and cannot inspect application-layer payloads; API Gateway is a managed service and does not use security groups in the traditional sense. Option D is wrong because network ACLs are stateless subnet-level filters that also operate at the network layer and cannot detect application-layer attacks.

20
Multi-Selectmedium

A security auditor is reviewing a Kubernetes cluster and identifies that containers are running as root with full Linux capabilities. Which TWO security measures would help mitigate container escape risks in this environment?

Select 2 answers
A.Set the container to run as a non-root user
B.Enable host networking mode
C.Use a privileged container
D.Drop all Linux capabilities except those needed
E.Mount the host filesystem as read-write
AnswersA, D

Running the container as a non-root user removes UID 0 inside the container, so a breakout attempt lands with unprivileged rights on the host and cannot modify protected files or kernel interfaces. This directly mitigates the root-with-full-capabilities risk the auditor identified.

Why this answer

Option A is correct because configuring the container to run as a non-root user (e.g., via securityContext.runAsUser or runAsNonRoot: true) removes the root privileges that an attacker could leverage to exploit kernel vulnerabilities or access host resources during a container escape attempt. Option D is correct because dropping all Linux capabilities and then adding back only those explicitly required (using securityContext.capabilities.drop: ["ALL"]) follows the principle of least privilege, eliminating dangerous capabilities like CAP_SYS_ADMIN, CAP_NET_ADMIN, and CAP_SYS_PTRACE that are commonly abused in container escape techniques. Option B is incorrect because enabling host networking mode actually increases risk by removing network namespace isolation, allowing the container to access host network interfaces and services directly.

Option C is incorrect because privileged containers disable nearly all security mechanisms (seccomp, AppArmor, capability restrictions) and grant full access to host devices, dramatically worsening escape risk. Option E is incorrect because mounting the host filesystem as read-write gives the container direct write access to host files, enabling tampering with system binaries or configuration to facilitate escape and persistence.

Exam trap

The trap is that 'privileged container' and 'host networking' sound like advanced features that might improve security, when in fact they are the exact misconfigurations that enable container escapes.

21
Multi-Selecthard

A DevOps team is implementing a secure container supply chain. Which THREE practices should they adopt to ensure image integrity and prevent tampering?

Select 3 answers
A.Sign container images using Cosign
B.Use admission controllers like Kyverno to verify signatures
C.Use the 'latest' tag for base images
D.Store images in a public registry
E.Generate attestation using in-toto
AnswersA, B, E

Cosign signs container images with cryptographic keys, producing a signature stored alongside the image in the registry. This gives verifiable provenance, satisfying the supply-chain integrity requirement by letting downstream systems confirm the image was not tampered with after signing.

Why this answer

Option A is correct because Cosign (part of the Sigstore project) cryptographically signs container images, producing a signature that can later be verified to prove the image was built by a trusted identity and has not been altered. Option B is correct because admission controllers such as Kyverno (or OPA Gatekeeper, Connaisseur) enforce policy at the Kubernetes API server, rejecting any pod whose image lacks a valid Cosign signature, thereby blocking tampered or unsigned images from running. Option E is correct because in-toto attestations capture signed, verifiable metadata about the build process (e.g., SLSA provenance), letting the team prove how and from what source an image was produced, which is central to supply-chain integrity.

Option C is not appropriate because the mutable 'latest' tag provides no immutability or version pinning, making it impossible to guarantee which image is deployed and undermining tamper detection. Option D is not appropriate because a public registry exposes images to unauthorized pulls and potential tampering, whereas a private, access-controlled registry with immutable tags is the secure choice.

Exam trap

The trap is that 'latest' tag and 'public registry' sound convenient and are common defaults, so candidates may select them as valid practices when they actually undermine integrity and tamper prevention.

22
MCQmedium

A healthcare organization stores PHI in an Amazon S3 bucket. An auditor finds that objects are encrypted with SSE-S3, and the organization wants to demonstrate that it controls the encryption keys and can audit their use independently of AWS-managed keys. Which change best satisfies this requirement while minimizing application changes?

A.Configure SSE-C with a customer-provided key sent on every request via the x-amz-server-side-encryption-customer-key header.
B.Switch the bucket to SSE-KMS using a customer managed key in AWS KMS, and grant the application role kms:Decrypt and kms:GenerateDataKey permissions.
C.Keep SSE-S3 but enable S3 Object Lock in compliance mode and versioning to prevent unauthorized key access.
D.Enable client-side encryption in the application using a locally stored AES-256 key and upload the encrypted objects to S3.
AnswerB

SSE-KMS with a customer managed key gives the organization control over key policy, rotation, and usage auditing via CloudTrail, which directly satisfies the auditor's requirement. Applications continue to use the standard S3 API; only IAM permissions for the KMS key are added. This minimizes code changes while providing independent key control and auditability.

Why this answer

SSE-KMS with a customer managed key allows the organization to define the key policy, control rotation, and audit every cryptographic operation through CloudTrail. Applications continue to use the standard S3 API with only additional IAM permissions on the KMS key, so code changes are minimal. This is the cleanest way to demonstrate independent key control and usage auditing.

Exam trap

The trap here is confusing 'customer controlled keys' with 'customer managed keys'; SSE-C gives control but shifts all key handling into the application, which is far more invasive than SSE-KMS.

23
MCQhard

A financial services company runs a regulated workload on a public cloud. The security team must ensure that all data at rest in the cloud provider's block storage service is encrypted with keys that the company controls and can revoke immediately. The company also needs to prove to auditors that the cloud provider cannot access the plaintext data. Which approach BEST meets these requirements?

A.Use provider-managed encryption keys with automatic rotation enabled, and rely on the provider's attestation reports for audit evidence.
B.Use a cloud provider's key management service to generate a customer-managed key (CMK) and enable automatic rotation, while the provider manages the underlying HSM.
C.Implement client-side encryption before writing data to block storage, using a customer-managed key stored in an external key management system.
D.Enable server-side encryption with customer-provided keys (SSE-C), where the company supplies the key with each API request but the provider stores the encrypted data.
AnswerC

Client-side encryption ensures data is encrypted before it reaches the cloud provider, so the provider never sees plaintext. Storing the key in an external KMS that the company controls allows immediate revocation and provides audit evidence that the provider cannot access the key. This directly satisfies all stated requirements: customer control, immediate revocation, and provable provider inaccessibility.

Why this answer

Client-side encryption with an externally managed key ensures the cloud provider never receives plaintext and cannot access the key. The company retains full control and can revoke the key instantly, and auditors can verify that the provider has no path to the plaintext. Other options either leave key control with the provider or do not provide provable inaccessibility, failing the regulatory requirements.

Exam trap

The trap here is confusing customer-managed keys in the provider's KMS with true customer-controlled keys, when only client-side encryption with external key storage guarantees the provider cannot access plaintext.

24
Multi-Selecthard

A cloud architect is designing a defense-in-depth strategy for a containerized application. Which THREE practices should be implemented to secure the container supply chain?

Select 3 answers
A.Sign images using Cosign
B.Always use the 'latest' tag for base images
C.Run containers with root privileges by default
D.Use immutable image tags (e.g., commit hash)
E.Scan images for CVEs with Trivy
AnswersA, D, E

Cosign signing creates a verifiable cryptographic attestation binding each image digest to a trusted publisher identity. This satisfies the supply-chain integrity constraint by enabling admission controllers to reject unsigned or tampered images before deployment, ensuring only artefacts built through approved pipelines reach the container runtime.

Why this answer

Option A is correct because signing images with Cosign (part of the Sigstore project) creates verifiable cryptographic signatures that let Kubernetes admission controllers or CI/CD pipelines confirm an image's provenance and integrity before deployment, preventing tampered or unauthorized images from entering the supply chain. Option D is correct because immutable tags such as a Git commit hash or digest guarantee that the exact audited artifact is deployed and cannot be silently overwritten, unlike mutable tags that can be repointed to different content. Option E is correct because scanning images with Trivy detects known CVEs in OS packages and language dependencies, enabling vulnerabilities to be caught and remediated early in the build pipeline.

Option B is not appropriate because the 'latest' tag is mutable and non-deterministic, so builds become unreproducible and can pull in unvetted or vulnerable base images. Option C is not appropriate because running containers as root violates least privilege and dramatically increases the blast radius if a container is compromised; containers should run as a non-root user.

Exam trap

CCSP often tests the misconception that encryption or scanning alone secures the supply chain, when the exam expects you to recognize that signing (integrity), immutable tags (reproducibility), and CVE scanning (vulnerability) are three distinct, complementary controls.

25
MCQhard

A healthcare organization runs a critical workload on Azure virtual machines. The security team wants to ensure that the VMs are protected against rootkit and kernel-level malware that could persist across reboots. They need a solution that can detect and alert on suspicious kernel driver loads and provide file integrity monitoring. Which Azure service should they implement?

A.Azure Defender for Servers
B.Azure Network Watcher
C.Azure Sentinel
D.Azure Security Center (standard tier)
AnswerA

Azure Defender for Servers (part of Microsoft Defender for Cloud) provides advanced threat protection for VMs, including file integrity monitoring, detection of suspicious kernel driver loads, and behavioral analytics. It can alert on rootkits and other kernel-level anomalies. This service is designed to meet the requirement for detecting and alerting on kernel-level malware and file integrity changes.

Why this answer

Azure Defender for Servers, a component of Microsoft Defender for Cloud, provides endpoint detection and response, file integrity monitoring, and kernel-level threat detection. It can identify suspicious kernel driver loads and rootkit behavior, alerting security teams. Other services like Network Watcher focus on network diagnostics, Sentinel is a SIEM, and the outdated Security Center standard tier is superseded by Defender for Servers.

Exam trap

The trap here is selecting Azure Sentinel or Network Watcher for endpoint-level kernel monitoring, when only Defender for Servers provides that host-based protection.

26
MCQeasy

A startup runs a three-tier web application on cloud virtual machines. The database tier must accept connections only from the application tier and never from the internet. Which cloud network security control should the team implement to enforce this requirement with the least operational overhead?

A.A network ACL on the database subnet denying all inbound traffic
B.A host-based firewall rule on each database VM allowing the application tier's public IP address
C.A security group on the database instances allowing only the application tier's security group as source
D.A web application firewall inspecting SQL traffic bound for the database
AnswerC

Security groups can reference another security group as a source, so the database rule permits traffic only from instances that carry the application tier's group membership. As the application tier scales in or out, membership updates automatically, requiring no rule edits, which satisfies the requirement with minimal ongoing operational effort.

Why this answer

Referencing the application tier's security group as the source of the database rule creates a dynamic, identity-based allow that follows instances as they scale. Because membership is managed automatically, the team avoids editing CIDR ranges or host firewalls whenever the application tier changes, meeting the segmentation goal with the least ongoing effort.

Exam trap

The trap here is choosing a subnet-level deny or a public IP allow, which either blocks legitimate traffic or requires constant manual updates as the application tier scales.

27
MCQmedium

A cloud architect is designing a VPC for a three-tier application. The web servers need to be accessible from the internet, while the application servers should only be reachable from the web servers, and the database servers should be isolated from all other traffic except the application servers. Which VPC design best meets these requirements?

A.Web servers in a public subnet, app and database servers in a single private subnet
B.All servers in a private subnet with a NAT gateway
C.All servers in a single public subnet with security groups
D.Web servers in a public subnet, app servers in a private subnet, databases in an isolated subnet with appropriate security groups
AnswerD

Placing web servers in a public subnet, app servers in a private subnet and databases in an isolated subnet, each governed by security groups, enforces the required traffic flow: internet to web only, web to app, and app to database.

Why this answer

A three-tier design requires three distinct network zones: a public subnet for internet-facing web servers, a private subnet for application servers reachable only from the web tier, and an isolated (private, no NAT/IGW route) subnet for databases reachable only from the app tier. Security groups enforce the tier-to-tier traffic rules (web SG allows 80/443 from internet; app SG allows app port from web SG; DB SG allows DB port from app SG). This layered segmentation is the canonical defense-in-depth VPC pattern.

Exam trap

CCSP often tests the misconception that a single private subnet with security groups is sufficient segmentation, when the exam expects recognition that each trust tier (web, app, DB) requires its own subnet and security group boundary.

How to eliminate wrong answers

Option A is wrong because placing app and database servers in the same private subnet collapses two trust tiers into one, so a compromised app server can directly reach the database without an additional security boundary. Option B is wrong because putting all servers in a private subnet with a NAT gateway removes the public entry point needed for internet-facing web servers and provides no tier separation. Option C is wrong because placing all servers in a single public subnet exposes the app and database tiers to the internet and eliminates network segmentation entirely, violating least privilege.

28
MCQeasy

A cloud operations team is configuring a virtual private cloud (VPC) and needs to control both inbound and outbound traffic at the subnet level. The team wants to ensure that any traffic leaving the subnet is explicitly allowed, and that responses to inbound requests are automatically permitted. Which VPC component should the team configure?

A.Security groups, because they are stateful and evaluate all traffic at the instance level.
B.Network ACLs, because they are stateless and can enforce explicit allow/deny rules for both inbound and outbound traffic at the subnet boundary.
C.VPC flow logs, because they capture metadata about traffic and can be used to enforce outbound restrictions.
D.Route tables, because they determine which subnet traffic is directed to and can block unauthorized destinations.
AnswerB

Network ACLs are stateless and operate at the subnet level. They require explicit rules for both inbound and outbound traffic, and return traffic must be allowed by an outbound rule. This matches the requirement to control traffic at the subnet level with explicit outbound allowances. They are the correct component for subnet-level traffic filtering in a VPC.

Why this answer

Network ACLs are stateless and operate at the subnet level, requiring explicit rules for both inbound and outbound traffic. This makes them the correct choice for controlling traffic at the subnet boundary with explicit outbound allowances. Security groups are stateful and instance-level, route tables direct traffic without filtering, and flow logs only record metadata without enforcement.

Exam trap

The trap here is assuming that security groups can provide subnet-level control because they are stateful, when in fact they operate at the instance level and cannot enforce explicit outbound rules at the subnet boundary.

29
MCQeasy

Which of the following is a primary benefit of using immutable tags for container images in a production registry?

A.Improved build performance
B.Automatic vulnerability scanning
C.Consistent and reproducible deployments
D.Reduced storage cost
AnswerC

Immutable tags map a fixed tag to one digest, so every deployment pulls byte-identical content. This eliminates drift between environments and gives the consistent, reproducible deployments the stem asks for, unlike mutable tags that can be overwritten silently.

Why this answer

Immutable tags prevent accidental overwriting of image tags, ensuring that the same tag always refers to the same image, which aids in traceability and rollback.

30
MCQeasy

In a cloud VPC, what is the difference between security groups and network ACLs (NACLs)?

A.Security groups are stateful and support allow rules only; NACLs are stateless and support allow and deny rules
B.Security groups support allow and deny rules; NACLs support only allow
C.Security groups are stateless and NACLs are stateful
D.Security groups and NACLs are both stateless
AnswerA

Security groups operate at the instance level, are stateful, and permit allow rules only. NACLs operate at the subnet level, are stateless, and support both allow and deny rules, so return traffic must be explicitly permitted in each direction.

Why this answer

Security groups are stateful—return traffic for an allowed inbound connection is automatically permitted—and they support only allow rules, with an implicit deny for anything not explicitly allowed. NACLs are stateless—each direction must be explicitly allowed, including ephemeral return ports—and they support both allow and deny rules, evaluated in numbered order. This stateful/stateless and allow-only/allow-deny distinction is the core difference.

Exam trap

CCSP often tests the stateful/stateless and allow-only/allow-deny distinction, and candidates frequently reverse the two (e.g., thinking SGs support deny or that NACLs are stateful), which is exactly the trap this question sets.

How to eliminate wrong answers

Option B is wrong because it reverses the rule types: security groups do not support deny rules (only allow), and NACLs do support deny rules in addition to allow. Option C is wrong because it reverses the statefulness: security groups are stateful, and NACLs are stateless. Option D is wrong because it incorrectly states both are stateless; security groups are stateful, which is why return traffic is automatically allowed.

31
MCQeasy

Which hypervisor technology is used to provide direct device access to a VM, improving performance and isolation for I/O operations?

A.IOMMU
B.CPU pinning
C.Virtual switches
D.Memory ballooning
AnswerA

IOMMU (Input-Output Memory Management Unit) maps device DMA requests to guest physical addresses, letting a VM access hardware directly while confining each device to its assigned memory region. This delivers near-native I/O performance and enforces isolation between guests, satisfying the stem's requirement for direct device access.

Why this answer

IOMMU (Input-Output Memory Management Unit) provides direct device access to a VM by translating device DMA addresses through the hypervisor's memory mapping, enabling safe passthrough of physical devices. This improves I/O performance and maintains isolation by preventing devices from accessing memory outside their assigned VM. It is the hardware feature that underpins secure device assignment.

Exam trap

The trap is confusing CPU or memory optimization features with I/O isolation — candidates must recognize IOMMU as the hardware mechanism specifically enabling safe direct device access.

How to eliminate wrong answers

Option B is wrong because CPU pinning binds vCPUs to physical cores to reduce scheduling overhead; it does not provide direct device access or I/O isolation. Option C is wrong because virtual switches handle network traffic between VMs and external networks, not direct device passthrough for I/O. Option D is wrong because memory ballooning reclaims unused guest memory to optimize host memory usage and has no role in device access or I/O isolation.

32
MCQeasy

A cloud security architect is designing a multi-tenant environment on a hypervisor. Which hypervisor type provides the most robust isolation between tenant virtual machines by running directly on the hardware without a host operating system?

A.Type 2 hosted hypervisor (e.g., VirtualBox)
B.Paravirtualized hypervisor (e.g., Xen)
C.Container runtime (e.g., Docker)
D.Type 1 bare-metal hypervisor (e.g., VMware ESXi)
AnswerD

A Type 1 hypervisor runs directly on bare metal, so each tenant VM's isolation boundary is enforced by the hypervisor kernel itself rather than a general-purpose host OS. That removes the host operating system's larger attack surface, satisfying the requirement for the most robust isolation between tenants.

Why this answer

A Type 1 bare-metal hypervisor (e.g., VMware ESXi) runs directly on the hardware without an underlying host operating system, providing the most robust isolation between tenant VMs. This architecture reduces the attack surface and ensures that each VM is isolated from others and from the hypervisor management layer.

Exam trap

The trap here is assuming that paravirtualized hypervisors provide the most isolation; candidates might think Xen is more secure because it is often used in cloud environments, but the question emphasizes 'without a host operating system,' which points to Type 1 bare-metal hypervisors like ESXi.

How to eliminate wrong answers

Option A is wrong because a Type 2 hosted hypervisor runs on top of a host OS, which introduces additional overhead and potential security vulnerabilities, reducing isolation. Option B is wrong because paravirtualized hypervisors like Xen can be Type 1, but the question specifies 'without a host operating system' and Xen can run in both modes; however, the most robust isolation is typically associated with Type 1 bare-metal hypervisors like ESXi, and Xen's paravirtualization requires modified guests, which may not provide the same level of isolation as full hardware virtualization. Option C is wrong because container runtimes like Docker share the host OS kernel, providing less isolation than hypervisors.

33
MCQmedium

During an audit of a containerized application, you notice that containers are running with the --privileged flag. Which of the following is the most significant security risk associated with this configuration?

A.Container escape to the host
B.Increased memory consumption
C.Inability to use secure base images
D.Excessive network bandwidth usage
AnswerA

The --privileged flag grants the container all Linux capabilities and unrestricted device access, disabling the namespace and cgroup barriers that normally confine it. An attacker inside can then mount the host filesystem or manipulate kernel interfaces to escape onto the host.

Why this answer

Privileged containers have nearly all capabilities of the host, significantly increasing the risk of container escape and host compromise.

34
Multi-Selecteasy

A company is deploying a serverless function in AWS Lambda that needs to access a private RDS database. Which TWO configurations are necessary for secure access?

Select 2 answers
A.Disable TLS for the database connection
B.Configure VPC integration for the Lambda function
C.Attach an Internet Gateway to the Lambda function
D.Assign a public IP address to the Lambda function
E.Create an execution role with permissions to the RDS database
AnswersB, E

VPC integration allows Lambda to access resources in a VPC.

Why this answer

Lambda functions must be attached to a VPC using VPC integration to access resources inside a private subnet, such as an RDS database. Without VPC integration, the Lambda function runs in an AWS-managed VPC and cannot reach resources in the customer’s VPC. This configuration requires the Lambda function to be associated with the same VPC, subnets, and security groups as the RDS instance.

Exam trap

The CCSP exam often tests the misconception that Lambda functions can directly access private resources without VPC integration, or that public IPs or Internet Gateways are needed for private connectivity, leading candidates to select options like C or D instead of recognizing the necessity of VPC integration and proper IAM roles.

35
MCQhard

A serverless function needs to access a private RDS database inside a VPC. What configuration is required to enable this without using public IP addresses?

A.Store database credentials in the function code
B.Use a NAT Gateway to allow inbound traffic
C.Place the Lambda function inside the VPC using VPC configuration
D.Attach an Internet Gateway to the VPC
AnswerC

Placing the Lambda function inside the VPC via VPC configuration gives it an elastic network interface in a private subnet, allowing it to reach the RDS instance over private IP addresses. No public IP or internet gateway is required for the database connection.

Why this answer

Serverless functions can be configured with VPC integration to access resources inside a VPC via private IP.

36
MCQhard

A cloud security engineer is implementing API Gateway security for a public-facing API. Which combination of controls best protects against both injection attacks and excessive usage?

A.IAM authentication and VPC endpoint
B.JWT validation and WAF integration
C.WAF integration and rate limiting
D.API keys and TLS enforcement
AnswerC

WAF integration inspects HTTP requests and blocks injection payloads such as SQL or command strings, while rate limiting caps requests per client to prevent abuse and denial-of-service. Together they satisfy both the injection and excessive-usage constraints.

Why this answer

WAF integration (C) inspects and filters HTTP requests to block injection attacks like SQLi and XSS, while rate limiting throttles excessive usage to prevent abuse and DoS. Together they address both the content-based threat (injection) and the volume-based threat (excessive usage) in a single combination. This pairing is the standard API Gateway protection pattern for public-facing APIs.

Exam trap

CCSP often tests whether candidates can map threats to controls — the trap is picking authentication or encryption options that sound secure but do not address injection payload inspection or request-volume throttling.

How to eliminate wrong answers

Option A is wrong because IAM authentication and VPC endpoints control access and network path but do not inspect request payloads for injection or throttle request volume. Option B is wrong because JWT validation authenticates callers and WAF blocks injection, but neither addresses excessive usage — there is no rate limiting control. Option D is wrong because API keys provide identification/quota tracking and TLS enforces encryption in transit, but neither inspects payloads for injection nor robustly throttles abusive volume.

37
MCQmedium

A financial services company runs sensitive workloads on a public IaaS cloud. The security team wants to cryptographically prove to auditors that the virtual machine hosting their data booted an unmodified, approved hypervisor and firmware image. Which cloud infrastructure security capability should they require from the provider?

A.Full-disk encryption of the guest operating system volumes
B.Measured boot with attestation using a virtual TPM
C.Security groups restricting inbound management ports
D.Immutable infrastructure with golden VM images
AnswerB

A virtual TPM records hashes of firmware, bootloader, and hypervisor components into platform configuration registers during the boot chain, and remote attestation lets the tenant verify those measurements against a known-good baseline. This gives cryptographic evidence that the platform was not tampered with, directly satisfying the auditor's requirement for proof of an untampered boot.

Why this answer

Measured boot combined with remote attestation uses a virtual TPM to hash each stage of the boot chain and expose those measurements for verification. Because the auditor needs cryptographic proof that firmware and hypervisor code were unmodified, this is the only listed control that observes the platform boot itself rather than the guest workload or network perimeter.

Exam trap

The trap here is assuming that guest-level controls such as disk encryption or hardened images can attest to the integrity of the provider-controlled hypervisor and firmware beneath them.

38
MCQmedium

A security team is reviewing container image supply chain security. Which tool is specifically designed for signing container images to ensure integrity and provenance?

A.Kube-bench
B.Clair
C.Cosign
D.Trivy
AnswerC

Cosign signs and verifies container images using keys or keyless OIDC identities, producing signatures that establish image integrity and provenance. It directly satisfies the supply chain requirement by letting deployments reject unsigned or tampered images before they run.

Why this answer

Cosign (C) is a tool from the Sigstore project specifically designed to sign, verify, and attach attestations to container images, providing integrity and provenance guarantees in the supply chain. It supports keyless signing via OIDC and integrates with registries and admission controllers. This makes it the purpose-built answer for image signing.

Exam trap

CCSP often tests tool-purpose recognition — the trap is confusing vulnerability scanners (Trivy, Clair) or compliance tools (Kube-bench) with signing tools, when only Cosign provides cryptographic image signing and provenance.

How to eliminate wrong answers

Option A is wrong because Kube-bench checks Kubernetes cluster configuration against CIS benchmarks — it is a compliance/configuration auditing tool, not an image signing tool. Option B is wrong because Clair is a static vulnerability scanner for container images; it identifies CVEs but does not sign or verify image provenance. Option D is wrong because Trivy is also a vulnerability and misconfiguration scanner for images, filesystems, and IaC — it detects issues but does not provide cryptographic signing or provenance attestation.

39
MCQmedium

A security team implements Kubernetes RBAC. They want to ensure that a service account can only create pods in the 'dev' namespace. Which RBAC resource should they use?

A.ClusterRole and ClusterRoleBinding
B.Role and RoleBinding in the 'dev' namespace
C.PodSecurityPolicy (deprecated)
D.NetworkPolicy
AnswerB

A Role defines permissions within a single namespace, and a RoleBinding grants those permissions to the service account only in that namespace. This satisfies the stem's constraint that pod creation is limited to the 'dev' namespace, unlike ClusterRole and ClusterRoleBinding.

Why this answer

RBAC uses Role and RoleBinding for namespace-scoped permissions. ClusterRole and ClusterRoleBinding are cluster-scoped. A Role with permissions to create pods in the 'dev' namespace, bound via RoleBinding, achieves the goal.

40
Multi-Selecthard

A security team is deploying a Kubernetes cluster on a cloud platform and wants to harden the worker nodes against container breakout and privilege escalation. They are reviewing kubelet and container runtime configurations. Which TWO of the following measures are MOST effective at reducing the attack surface and preventing a compromised container from gaining node-level privileges? (Choose two.)

Select 2 answers
A.Enable the kubelet read-only port and disable anonymous authentication to the kubelet API.
B.Run containers with a read-only root filesystem and drop all Linux capabilities except those explicitly required.
C.Configure the container runtime to use the overlay2 storage driver with a dedicated volume for each container.
D.Use a Pod Security Admission policy that enforces the restricted profile, which requires non-root execution and disallows privilege escalation.
E.Enable audit logging on the Kubernetes API server and ship logs to a central SIEM for alerting.
AnswersB, D

A read-only root filesystem prevents attackers from writing malicious binaries or modifying system files inside the container, and dropping unnecessary Linux capabilities removes the ability to perform privileged operations such as mounting filesystems or loading kernel modules. Together they significantly reduce the container's ability to escalate privileges or break out to the node.

Why this answer

Hardening worker nodes against container breakout requires preventive controls that limit what a compromised container can do. Running with a read-only root filesystem and dropping unnecessary Linux capabilities removes the tools and privileges needed for escalation. Enforcing the restricted Pod Security Standard via Pod Security Admission ensures workloads cannot run as root, cannot escalate privileges, and must meet seccomp and capability restrictions.

Together these measures significantly reduce the attack surface and block common escape techniques.

Exam trap

The trap here is selecting detective controls like audit logging or general kubelet hardening instead of the preventive, workload-level restrictions that actually stop privilege escalation and breakout.

41
Multi-Selectmedium

An organization uses Azure Functions and wants to secure its API endpoints exposed via Azure API Management. Which TWO security controls should they implement at the API Gateway level?

Select 2 answers
A.Configure IP whitelisting for all users
B.Store secrets in Azure Function environment variables
C.Enable TLS enforcement
D.Implement JWT validation
E.Disable API keys
AnswersC, D

TLS enforcement at the gateway encrypts traffic between clients and API Management, preventing credential and token interception in transit. This satisfies the requirement to secure exposed API endpoints at the gateway layer, independent of backend Azure Functions configuration.

Why this answer

Option C (Enable TLS enforcement) is correct because enforcing TLS at the API Management gateway ensures all client-to-gateway traffic is encrypted in transit using HTTPS, protecting credentials and tokens from interception, and API Management supports configuring the minimum TLS version and cipher suites on the gateway. Option D (Implement JWT validation) is correct because API Management has a built-in validate-jwt policy that verifies the signature, issuer, audience, and expiration of OAuth 2.0/OpenID Connect bearer tokens at the gateway, so unauthenticated or tampered requests are rejected before reaching the backend Functions. Option A is not a gateway-level authentication control and whitelisting 'all users' is contradictory and impractical for public APIs.

Option B is a backend configuration concern for the Function app, not a control applied at the API Gateway. Option E is wrong because disabling API keys removes a subscription-based access control rather than adding security at the gateway.

42
MCQhard

A cloud security team is using AWS Lambda functions to process sensitive data. The functions are triggered by Amazon S3 events and write to an Amazon DynamoDB table. The team wants to ensure that the Lambda functions have only the permissions they need and that any compromised function cannot access other AWS resources. Which of the following is the MOST effective approach?

A.Attach a resource-based policy to the DynamoDB table that allows all Lambda functions in the account to write to it.
B.Create a separate IAM role for each Lambda function with permissions scoped to only the specific S3 bucket and DynamoDB table it needs.
C.Use AWS Lambda environment variables to store IAM credentials and rotate them regularly.
D.Create a single IAM role with broad permissions to all necessary services and assign it to all Lambda functions.
AnswerB

Using a distinct IAM role per function with narrowly scoped permissions ensures that each function can only access its required resources. If one function is compromised, the attacker cannot use its role to access other resources. This is the most effective way to enforce least privilege and limit lateral movement.

Why this answer

The most effective approach is to create a separate IAM role for each Lambda function with permissions scoped to only the resources that function needs. This enforces least privilege and ensures that a compromised function cannot access other AWS resources. Other options either grant excessive permissions, use insecure credential storage, or are overly permissive.

Exam trap

The trap here is thinking that a single role with broad permissions or resource-based policies are sufficient, when in fact per-function roles with least privilege are needed to contain a compromised function.

43
Multi-Selecthard

A cloud operations team is hardening the management plane of a production VPC. The security architect wants to reduce the risk of credential compromise and lateral movement through management interfaces. Which TWO measures best address this goal? (Choose two.)

Select 2 answers
A.Enforce least privilege on management roles and require multi-factor authentication for privileged sessions
B.Enable verbose API logging and forward all management events to a central log repository
C.Place management interfaces behind a bastion host reachable only from a corporate IP range
D.Replace long-lived access keys with short-lived credentials issued through a federated identity provider
E.Increase the password complexity policy for all administrative accounts to twenty characters
AnswersA, D

Least privilege limits what a compromised management credential can do, and mandatory multi-factor authentication makes stolen passwords or tokens insufficient on their own. Together they constrain both the likelihood of credential compromise succeeding and the scope of damage if it does. This combination is a core control for protecting administrative interfaces in cloud environments.

Why this answer

Reducing management plane risk centers on making credentials short-lived and limiting what they can do. Federated identity with temporary credentials removes static keys that can be stolen and reused, while least privilege plus multi-factor authentication constrains the impact of any single compromised session. Together these directly attack credential compromise and lateral movement, whereas logging is detective and password length and bastion placement are secondary hardening steps.

Exam trap

The trap here is selecting detective controls such as logging or perimeter controls such as bastion hosts, when the goal calls for preventive controls that shorten credential life and limit privilege.

44
MCQmedium

A container runtime is configured to drop all Linux capabilities, use a read-only root filesystem, and apply a Seccomp profile. Which primary security goal does this configuration achieve?

A.Image integrity verification
B.Ensuring immutability of containers
C.Prevention of container escape
D.Network segmentation between pods
AnswerC

Dropping all Linux capabilities removes the privileges an attacker needs to break out of the container's namespace isolation, while the read-only root filesystem and Seccomp profile block the syscalls and filesystem writes that privilege-escalation exploits rely on. Together these harden the container boundary against escape.

Why this answer

Dropping all Linux capabilities, using a read-only root filesystem, and applying a Seccomp profile collectively harden the container against privilege escalation and syscall-based attacks that are commonly used in container escape techniques. These controls limit what a compromised process can do, making it much harder to break out of the container and access the host. Thus, the primary security goal is prevention of container escape.

Exam trap

CCSP often tests the confusion between runtime hardening controls and other security goals — candidates may pick immutability or image integrity when the combination of capabilities, read-only FS, and Seccomp specifically targets escape prevention.

How to eliminate wrong answers

Option A is wrong because image integrity verification involves signing and verifying container images (e.g., Docker Content Trust, cosign), not runtime restrictions like capabilities or Seccomp. Option B is wrong because immutability refers to preventing changes to the container's filesystem at runtime; while a read-only root filesystem supports immutability, the combination with capability dropping and Seccomp is broader than immutability alone. Option D is wrong because network segmentation between pods is achieved via network policies (e.g., Kubernetes NetworkPolicy, service mesh), not via capability or syscall restrictions.

45
MCQmedium

A DevOps engineer is configuring a Kubernetes cluster and wants to enforce that containers cannot run as root and cannot mount host paths. Which Kubernetes security mechanism should be used?

A.Pod Security Admission
B.Network policies
C.RBAC
D.Secrets management
AnswerA

Pod Security Admission enforces Pod Security Standards at the namespace level, with the restricted profile rejecting pods that run as root or mount host paths. This declaratively satisfies both constraints the DevOps engineer needs to enforce.

Why this answer

Pod Security Admission (PSA) is the built-in Kubernetes admission controller that enforces Pod Security Standards (Privileged, Baseline, Restricted) at the namespace level. The Restricted profile specifically prohibits running as root (via runAsNonRoot and allowPrivilegeEscalation: false) and blocks hostPath volume mounts, which is exactly what the engineer needs. It replaced the deprecated PodSecurityPolicy and is applied via namespace labels like pod-security.kubernetes.io/enforce=restricted.

Exam trap

The trap here is confusing admission-time pod security controls with runtime network or identity controls — candidates often pick Network Policies or RBAC because they sound like 'security,' but only PSA inspects the pod spec's securityContext and volume definitions.

How to eliminate wrong answers

Option B is wrong because Network Policies only control pod-to-pod and pod-to-external L3/L4 traffic flows; they have no visibility into container user IDs or volume mount types. Option C is wrong because RBAC governs which users/service accounts can perform API actions (verbs on resources), not the runtime security context of a container. Option D is wrong because Secrets management handles storage and retrieval of sensitive data like credentials and tokens; it does not constrain how a container executes or what it mounts.

46
Multi-Selectmedium

A security team is hardening a Kubernetes cluster for production workloads. Which THREE measures should they implement to improve runtime container security?

Select 3 answers
A.Mount the host filesystem as read-write in containers
B.Enable AppArmor or SELinux profiles
C.Drop all unnecessary Linux capabilities
D.Apply Seccomp profiles to restrict system calls
E.Use privileged containers for system daemons
AnswersB, C, D

These MAC systems enforce security policies on containers.

Why this answer

AppArmor and SELinux are Linux Security Modules (LSMs) that enforce mandatory access control (MAC) policies on containers. By applying these profiles, you restrict what processes inside a container can do—such as file access, network operations, and capability use—beyond the default discretionary access controls. This significantly reduces the attack surface and limits the impact of a container breakout.

Exam trap

ISC2 often tests the distinction between runtime security measures (like AppArmor, Seccomp, and capability dropping) versus build-time or network-level controls, and candidates may confuse privileged containers with necessary system daemons, forgetting that privileged mode bypasses all runtime security layers.

47
MCQhard

A cloud security engineer is designing network isolation for a multi-tier application in a single VPC. The database tier must accept connections only from the application tier, and the application tier must accept traffic only from the web tier. Which mechanism should the engineer use to enforce this at the instance level?

A.Network ACLs applied to the subnets hosting each tier
B.VPC flow logs analyzed by a security information and event management system
C.Security groups that reference other security groups as allowed sources
D.A route table that directs inter-tier traffic through a virtual appliance
AnswerC

Security groups are stateful, instance-level virtual firewalls that support referencing another security group as the source in an inbound rule. The database tier's group can allow traffic only from the application tier's group, and the application tier's group can allow traffic only from the web tier's group. This expresses tier isolation in terms of logical group membership rather than IP addresses, so it remains correct as instances scale.

Why this answer

Security groups are stateful and evaluated at the instance's elastic network interface, and they uniquely support referencing another security group as an allowed source. That lets the engineer define the database tier as reachable only from members of the application tier's group, and the application tier as reachable only from the web tier's group. This logical, identity-based rule set preserves isolation as instances scale and change IP addresses.

Exam trap

The trap here is assuming subnet-level network ACLs can express tier-to-tier trust, when only security groups can reference other security groups as sources for instance-level enforcement.

48
MCQhard

A cloud operations team is deploying a three-tier application across two AWS Availability Zones. The database tier must not be reachable from the internet, and the web tier must accept HTTPS from the public. The security architect wants defense in depth at both the subnet and instance levels. Which combination of controls BEST aligns with a layered network security design?

A.Place both tiers in public subnets and use network ACLs to restrict the database tier to the web tier's CIDR block, with security groups allowing all traffic within the VPC.
B.Use AWS WAF in front of the web tier and AWS Shield Advanced for the database tier, with security groups allowing 3306 from the VPC CIDR.
C.Place the web tier in a public subnet with a security group allowing 443 from 0.0.0.0/0 and a network ACL allowing 443 inbound; place the database tier in a private subnet with a security group allowing 3306 only from the web tier security group and a network ACL denying all internet CIDR ranges.
D.Place both tiers in private subnets, use a NAT gateway for web tier egress, and rely on security groups alone to control inbound traffic.
AnswerC

This design layers stateless network ACLs at the subnet boundary with stateful security groups at the instance level, which is the intended defense-in-depth model in a VPC. The database tier references the web tier's security group rather than a CIDR, so only authorized instances can connect. Denying internet CIDRs at the network ACL adds a second, independent barrier.

Why this answer

A layered VPC design uses network ACLs at the subnet boundary and security groups at the instance level, giving two independent enforcement points. Referencing the web tier's security group as the database source restricts access to authorized instances rather than broad CIDRs. Keeping the database in a private subnet and denying internet CIDRs at the network ACL completes the defense-in-depth model.

Exam trap

The trap here is treating security groups and network ACLs as interchangeable; they operate at different layers and a proper design uses both, with security group references instead of CIDR ranges for internal tiers.

49
MCQeasy

A serverless function needs to access a private database service without traversing the public internet. Which configuration should be used?

A.Assign a public IP to the serverless function
B.Configure the serverless function with virtual private cloud integration
C.Enable public access on the database service
D.Use a network address translation gateway to route traffic
AnswerB

VPC integration places the function's elastic network interfaces inside private subnets, so traffic to the database stays on the AWS private network and never routes through an internet gateway or NAT. This directly satisfies the requirement to avoid public internet traversal.

Why this answer

Virtual private cloud (VPC) integration allows the serverless function to be deployed inside a VPC, enabling private access to resources like a database service. Internet access is not required.

50
MCQeasy

Which of the following is a primary risk specific to virtual machine escape attacks in cloud environments?

A.Unauthorized access to other tenant VMs
B.Data corruption within the same VM
C.Increased latency in virtual networking
D.Denial of service to the attacker's own VM
AnswerA

A VM escape exploits a hypervisor or virtualisation flaw to break out of the guest boundary, letting the attacker execute code on the host. From there they can read or manipulate other tenants' VM memory and data, so unauthorised access to co-resident tenant VMs is the defining risk.

Why this answer

VM escape attacks occur when an attacker breaks out of the guest VM's isolation and gains access to the hypervisor or host. In a multi-tenant cloud environment, the hypervisor manages multiple tenants' VMs, so a successful escape can allow the attacker to access or compromise other tenants' VMs running on the same host. This cross-tenant access is the primary risk specific to cloud VM escape, as it violates the fundamental isolation guarantee of cloud computing.

Exam trap

The trap is selecting a generic attack impact (data corruption, DoS) instead of recognizing that the defining risk of VM escape in cloud is cross-tenant compromise due to shared hypervisor infrastructure.

How to eliminate wrong answers

Option B is wrong because data corruption within the same VM is a consequence of many attacks but not specific to escape; escape implies breaking isolation, not just corrupting local data. Option C is wrong because increased latency in virtual networking is a performance issue, not a security risk of escape. Option D is wrong because denial of service to the attacker's own VM is counterproductive and not a risk of escape; the attacker seeks to compromise others, not self-destruct.

51
MCQmedium

A security engineer is implementing container image security. They want to ensure that only signed images from a trusted registry can be deployed in the Kubernetes cluster. Which tool should they use to enforce this at the admission controller level?

A.Clair
B.Trivy
C.Cosign
D.Snyk Container
AnswerC

Cosign signs container images and stores signatures in the registry, letting an admission controller verify provenance before pods are admitted. This enforces the trusted-registry constraint at admission time, rejecting any unsigned or tampered image before it reaches the cluster.

Why this answer

Cosign is a tool from the Sigstore project that signs and verifies container images. It integrates with Kubernetes admission controllers (e.g., via Kyverno or OPA Gatekeeper policies) to enforce that only images with valid signatures from a trusted registry are deployed. This directly addresses the requirement to enforce signed images at admission time.

Exam trap

The trap is confusing vulnerability scanning tools (Clair, Trivy, Snyk) with image signing and verification tools (Cosign), leading candidates to pick a scanner when the requirement is signature enforcement.

How to eliminate wrong answers

Option A is wrong because Clair is a vulnerability scanner for container images, not a signing or admission enforcement tool. Option B is wrong because Trivy is also a vulnerability and misconfiguration scanner, not a signature verifier. Option D is wrong because Snyk Container scans for vulnerabilities and provides remediation advice, but does not enforce image signatures at admission.

52
MCQhard

In a Kubernetes environment, a security team wants to enforce that only images signed by a trusted authority can be deployed. Which component can be used to validate image signatures at admission time?

A.Network policies
B.Admission controller (e.g., OPA Gatekeeper)
C.RBAC policies
D.Secrets management with Vault
AnswerB

Admission controllers intercept API server requests before pods persist, so OPA Gatekeeper can query a signature-verification policy and reject unsigned or untrusted images. This enforces the trusted-authority constraint at admission time rather than relying on later scanning or runtime detection.

Why this answer

An admission controller such as OPA Gatekeeper can intercept requests to the Kubernetes API server before objects are persisted, allowing it to validate image signatures. By integrating with tools like Cosign or Notary, the admission controller can reject pods that use unsigned or untrusted images, enforcing the policy at deployment time.

Exam trap

The trap is confusing admission control with other Kubernetes security mechanisms like RBAC or network policies, leading candidates to pick a component that doesn't operate at admission time or doesn't handle image signatures.

How to eliminate wrong answers

Option A is wrong because Network policies control pod-to-pod network traffic, not image admission. Option C is wrong because RBAC policies govern who can perform actions on Kubernetes resources, not the content or provenance of images. Option D is wrong because Secrets management with Vault stores and manages secrets, but does not validate image signatures at admission.

53
MCQhard

A security analyst discovers that a container running in a Kubernetes cluster has been compromised. The attacker escalated privileges and accessed the host's kernel. Which of the following misconfigurations most likely allowed this container escape?

A.The container was run with the --privileged flag
B.The container was run with a default Seccomp profile
C.The container was run with a read-only root filesystem
D.The container was run with an AppArmor profile in enforce mode
AnswerA

The --privileged flag disables the default seccomp, AppArmor and capability restrictions, granting the container nearly all Linux capabilities plus access to host devices. That lets an attacker mount the host filesystem or load kernel modules, escaping to the host kernel.

Why this answer

Running a container with the --privileged flag disables container isolation and gives the container almost all capabilities of the host, including access to host devices and kernel. This allows an attacker who compromises the container to easily escape and access the host kernel, as seen in the scenario.

Exam trap

The trap is selecting a security-hardening option (Seccomp, read-only FS, AppArmor) as the cause of escape, when in fact those options prevent escape; the correct answer is the one that removes isolation.

How to eliminate wrong answers

Option B is wrong because a default Seccomp profile restricts system calls, making escape harder, not easier. Option C is wrong because a read-only root filesystem prevents modification of the container's filesystem, which hinders but does not enable escape. Option D is wrong because an AppArmor profile in enforce mode restricts container actions, reducing the likelihood of escape.

54
MCQmedium

A cloud security architect needs to allow an application in a VPC to access a cloud database service without traversing the public internet. Which feature should be implemented?

A.VPN Connection
B.Internet Gateway
C.Private Endpoint (Service Endpoint)
D.NAT Gateway
AnswerC

A Private Endpoint (Service Endpoint) maps the database service into the VPC's private address space, so traffic never traverses the public internet. This satisfies the constraint by keeping connectivity on the cloud provider's private backbone rather than via NAT or internet gateway.

Why this answer

Private Endpoint (also known as Service Endpoint or Private Link) enables private connectivity to cloud services without internet exposure.

55
MCQmedium

A company is migrating a legacy application to a cloud provider's infrastructure as a service (IaaS) platform. The security team must ensure that the hypervisor layer is patched and secured, and that tenants cannot access each other's memory or storage. According to the shared responsibility model, which party is responsible for securing the hypervisor and preventing cross-tenant access?

A.The cloud provider, because the hypervisor and underlying infrastructure are part of the provider's managed security scope.
B.A third-party auditor, because independent verification is required to ensure tenant isolation in multi-tenant environments.
C.The customer, because they are responsible for all security controls in IaaS.
D.Both parties share equal responsibility, with the customer patching the hypervisor and the provider monitoring for cross-tenant attacks.
AnswerA

In the shared responsibility model, the cloud provider is always responsible for the security of the cloud, which includes the hypervisor, physical hosts, and the network fabric. The provider patches and secures the hypervisor and enforces tenant isolation. The customer cannot perform these tasks in IaaS, so the provider must own them. This is the correct division of responsibility.

Why this answer

The cloud provider is responsible for securing the hypervisor and preventing cross-tenant access because these are part of the provider's managed infrastructure. Customers cannot access or patch the hypervisor in IaaS. The shared responsibility model always assigns the hypervisor, physical hosts, and network fabric to the provider, while the customer secures the guest OS, applications, and data.

Exam trap

The trap here is assuming that IaaS gives the customer responsibility for all layers, when the hypervisor and physical infrastructure always remain with the cloud provider.

56
Multi-Selecthard

A company is adopting a microservices architecture on Kubernetes and needs to ensure least privilege for pod-to-pod communication. Which THREE controls should be implemented?

Select 3 answers
A.Service accounts with minimal permissions
B.Network policies to allow only necessary traffic between pods
C.RBAC to limit what pods can do within the cluster
D.Pod Security Admission to enforce that containers run as root
E.Horizontal Pod Autoscaler
AnswersA, B, C

Service accounts bound to minimal RBAC permissions limit what API actions each pod identity can perform, so a compromised pod cannot escalate cluster-wide. This satisfies least privilege for pod-to-pod communication by constraining the credentials pods present to the API server.

Why this answer

Option A is correct because assigning each microservice a dedicated Kubernetes ServiceAccount with minimal RBAC permissions ensures pods authenticate to the API server with only the rights they actually need, which is a core least-privilege practice. Option B is correct because NetworkPolicy objects (enforced by a CNI plugin such as Calico or Cilium) provide default-deny ingress/egress and then explicitly allow only the required pod-to-pod flows on specific ports and protocols, directly restricting lateral movement. Option C is correct because RBAC Roles/ClusterRoles bound to those ServiceAccounts limit what pods can do within the cluster, such as which resources and verbs (get, list, watch, create) they may access, preventing privilege escalation.

Option D is not correct because Pod Security Admission enforcing containers to run as root is the opposite of least privilege; the restricted profile should require runAsNonRoot, drop capabilities, and disallow privileged containers. Option E is not correct because the Horizontal Pod Autoscaler only scales replica counts based on metrics like CPU or memory and has no bearing on authorization or network access control.

Exam trap

CCSP often tests whether candidates confuse scalability controls (HPA) or misconfigured security controls (running as root) with actual least-privilege mechanisms — always map each option to identity, authorization, or network enforcement.

57
MCQmedium

A cloud security architect is designing a multi-tenant IaaS deployment where tenants run untrusted workloads on shared physical hosts. The architect wants to reduce the risk of cross-tenant data remanence in the storage layer. Which control is MOST effective?

A.Enable server-side encryption with a single provider-managed key for the whole storage service.
B.Implement storage QoS and IOPS throttling to isolate tenant workloads on shared volumes.
C.Rely on the hypervisor's memory scrubbing between VM lifecycles to prevent data leakage.
D.Enable encryption at rest with per-tenant customer-managed keys and cryptographic erasure on deprovisioning.
AnswerD

Per-tenant customer-managed keys allow the provider to cryptographically shred data by destroying the tenant-specific key, so remanence risk is eliminated even if physical blocks are later reallocated to another tenant. This satisfies CCSP expectations for data isolation and secure disposal in multi-tenant storage.

Why this answer

Cryptographic erasure with per-tenant customer-managed keys is the strongest control against storage remanence in multi-tenant environments because destroying the key renders residual ciphertext unrecoverable. Provider-managed shared keys, memory scrubbing, and QoS controls do not address persistent-block reuse by other tenants, leaving confidentiality risk unresolved.

Exam trap

The trap here is assuming that encryption at rest with any key management scheme automatically solves data remanence, when only per-tenant keys enabling cryptographic erasure actually eliminate cross-tenant recovery risk.

58
Multi-Selecthard

A company is deploying a microservices architecture on Kubernetes and wants to implement supply chain security. Which THREE of the following practices should be adopted?

Select 3 answers
A.Signing container images with Cosign
B.Allowing all images from public registries
C.Scanning images for CVEs using Trivy
D.Using the :latest tag for all images
E.Configuring an admission controller like Kyverno to verify image signatures
AnswersA, C, E

Cosign signs container images with a private key, producing a verifiable signature stored in the registry alongside the image. This establishes provenance and integrity, letting downstream admission controls confirm the image was built by a trusted publisher before deployment.

Why this answer

Option A is correct because signing container images with Cosign (part of the Sigstore project) creates a verifiable cryptographic attestation of the image's provenance and integrity, which is a foundational supply chain security control. Option C is correct because scanning images for CVEs with Trivy detects known vulnerabilities in OS packages and application dependencies before deployment, enabling remediation prior to running workloads in the cluster. Option E is correct because an admission controller such as Kyverno can enforce policy at admission time, verifying Cosign signatures and rejecting unsigned or untrusted images so that only validated artifacts run in the cluster.

Option B is incorrect because allowing all images from public registries removes provenance controls and exposes the cluster to untrusted or malicious images. Option D is incorrect because using the :latest tag is mutable and non-deterministic, preventing reliable signature verification and reproducible, auditable deployments.

Exam trap

CCSP often tests whether candidates recognize that image signing alone is insufficient without enforcement — the trap is selecting signing and scanning but omitting the admission controller that actually blocks unsigned images at deploy time.

59
MCQeasy

A cloud operations team is deploying a web application behind a load balancer in a VPC. The application servers must be reachable only from the load balancer, never directly from the internet. Which configuration achieves this?

A.Place the application servers in a public subnet and attach a network ACL that denies inbound traffic from 0.0.0.0/0.
B.Keep the application servers in a public subnet but enable a host-based firewall on each instance.
C.Place the application servers in a private subnet and attach a security group that allows inbound traffic only from the load balancer's security group.
D.Assign elastic IP addresses to the application servers and restrict access using a VPN.
AnswerC

A private subnet removes the route to an internet gateway, and referencing the load balancer's security group as the source restricts traffic to that balancer. This layered approach ensures no direct internet path and no unauthorized source can reach the application servers.

Why this answer

Private subnets eliminate the internet route, and referencing the load balancer's security group as the allowed source ensures only that balancer can reach the application servers. Public subnets, host firewalls, and elastic IPs all leave direct internet reachability in place, so they fail the isolation requirement.

Exam trap

The trap here is believing that a network ACL or host firewall alone can isolate servers that still reside in a public subnet with an internet route, when subnet placement is the foundational control.

60
Multi-Selecthard

A cloud security team is designing the management plane for a regulated workload on a public IaaS platform. They must ensure that administrative access to the cloud console and APIs is strongly controlled. Which TWO measures best satisfy this requirement? (Choose two.)

Select 2 answers
A.Restrict administrative API calls to approved source networks using provider policy conditions
B.Issue long-lived access keys to automation accounts to simplify pipeline authentication
C.Deploy a content delivery network in front of the provider's management console endpoints
D.Enable verbose object storage access logging for all buckets in the account
E.Enforce phishing-resistant multifactor authentication for all administrative identities
AnswersA, E

Many cloud providers let administrators attach conditions to IAM policies that evaluate the source network of an API call. Requiring administrative actions to originate from a known corporate range or a bastion network means a stolen credential used from an attacker's location is rejected outright, adding a strong contextual control independent of the credential itself.

Why this answer

Protecting the management plane requires both strong authentication and contextual authorization. Phishing-resistant multifactor authentication stops credential theft, while policy conditions that restrict administrative API calls to approved source networks ensure that even a stolen credential cannot be replayed from an untrusted location. Together they address identity and context, which are the two levers tenants control over the provider's management plane.

Exam trap

The trap here is selecting logging or network acceleration measures that sound like security controls but only observe or optimize traffic rather than preventing unauthorized administrative access.

61
MCQeasy

Which of the following is a key difference between a security group and a network ACL in a VPC?

A.Security groups are stateless, while NACLs are stateful
B.Security groups are applied at the subnet level, while NACLs are applied at the instance level
C.Security groups support both allow and deny rules
D.Security groups are stateful, while NACLs are stateless
AnswerD

Security groups track connection state, so return traffic is automatically permitted regardless of inbound rules. Network ACLs evaluate each packet independently against their rules, requiring explicit inbound and outbound allowances for both directions of a flow.

Why this answer

Security groups are stateful, meaning return traffic is automatically allowed regardless of inbound rules. NACLs are stateless, requiring explicit inbound and outbound rules.

62
MCQmedium

A company uses Azure Functions for serverless data processing. To securely access an Azure SQL database, which of the following is the most secure method for managing the database connection string?

A.Embed the connection string in the function code and encrypt the code file
B.Store the connection string as an environment variable in the function app settings
C.Use Azure Policy to enforce encryption of the connection string at rest
D.Reference the connection string from Azure Key Vault using a managed identity
AnswerD

A managed identity lets Azure Functions authenticate to Key Vault without stored credentials, and the connection string is retrieved at runtime rather than embedded in code or configuration. This satisfies the stem's most-secure requirement by eliminating secrets from the application entirely.

Why this answer

Referencing the connection string from Azure Key Vault using a managed identity eliminates secrets from code and configuration entirely: the Function App authenticates to Key Vault via its Azure AD managed identity, and Key Vault returns the secret at runtime. This removes the need to store, rotate, or transmit the credential manually and is Microsoft's recommended pattern for secret management.

Exam trap

The trap is treating 'encrypted at rest' or 'environment variable' as equivalent to secure secret management; the exam expects you to know that only a dedicated secret store (Key Vault) accessed via managed identity removes the secret from code and configuration entirely.

How to eliminate wrong answers

Option A is wrong because embedding a connection string in code — even encrypted — still ships the secret with the artifact, exposes it to anyone with source or deployment access, and requires code changes to rotate. Option B is wrong because Function App settings (environment variables) are stored in plaintext in the Azure control plane, visible to anyone with Reader/Contributor access, and are not a secure secret store. Option C is wrong because Azure Policy enforces configuration compliance (e.g., requiring encryption at rest) but does not itself manage or retrieve secrets; encrypting a string that is still stored in app settings does not remove the exposure.

63
MCQeasy

A startup is designing its first cloud landing zone and wants a guardrail that prevents any principal in the organization from disabling AWS CloudTrail logging in any account, including the management account, while still allowing normal administrative work. Which control achieves this with the LEAST operational overhead?

A.A CloudWatch Logs metric filter on the CloudTrail log group that triggers an AWS Lambda function to restart the trail.
B.An IAM permissions boundary on every administrator role that denies the CloudTrail modification actions.
C.An organization-level service control policy attached to the root that denies cloudtrail:StopLogging, cloudtrail:DeleteTrail, and cloudtrail:UpdateTrail.
D.An AWS Config rule that detects when a trail is stopped and sends an Amazon SNS notification to the security team.
AnswerC

A service control policy attached at the organization root sets the maximum available permissions for every account in the organization, including the management account when applied at the root. Denying the trail-modification actions blocks the operation regardless of identity-based policy, giving a single preventive guardrail with no per-account maintenance.

Why this answer

An organization root service control policy denies the trail-modification API calls for all principals in every account, making the guardrail preventive rather than detective and requiring no per-account upkeep. Detection rules, permissions boundaries, and remediation automation either act after the fact or leave uncovered principals.

Exam trap

The trap here is reaching for a detective control such as AWS Config or a CloudWatch alarm when the requirement is to prevent the action from succeeding at all.

64
Multi-Selectmedium

A cloud security team is designing network security for a multi-VPC architecture in AWS. Which TWO of the following are valid considerations for VPC peering?

Select 2 answers
A.VPC peering can be used to connect on-premises networks
B.VPC peering requires an internet gateway for communication
C.VPC peering is a one-to-one relationship
D.VPC peering supports transitive routing across multiple VPCs
E.VPC peering allows private IP connectivity between VPCs
AnswersC, E

VPC peering links exactly two VPCs, so each peering connection is a discrete one-to-one relationship rather than a transitive hub. This satisfies the multi-VPC design constraint: traffic cannot route through a peered VPC to reach a third, requiring explicit mesh or transit gateway topologies.

Why this answer

Option C is correct because a VPC peering connection is strictly a one-to-one relationship between exactly two VPCs; you cannot attach a single peering connection to more than two VPCs, and each pair requires its own peering connection. Option E is correct because VPC peering routes traffic using private IPv4 or IPv6 addresses between the peered VPCs, so instances communicate over the AWS private network without traversing the public internet. Option A is incorrect because connecting on-premises networks to a VPC requires AWS Site-to-Site VPN or AWS Direct Connect, not VPC peering.

Option B is incorrect because peering traffic flows over the AWS backbone and does not require an internet gateway, NAT device, or virtual private gateway. Option D is incorrect because VPC peering does not support transitive routing; to reach a third VPC you must establish a direct peering connection (or use a transit gateway).

Exam trap

CCSP often tests the misconception that VPC peering supports transitive routing or requires an internet gateway, confusing it with VPN or Transit Gateway capabilities.

65
MCQeasy

A DevOps team is building a container image for a cloud-native application. To minimize the attack surface and reduce the number of vulnerabilities, which type of base image should they use?

A.A full distribution image like Ubuntu
B.An Alpine-based image
C.A distroless image
D.The 'latest' tag of any official image
AnswerC

A distroless image contains only the application and its runtime dependencies, omitting package managers, shells and other OS utilities. This directly minimises the attack surface and vulnerability count, satisfying the stem's requirement to reduce exploitable components in the container image.

Why this answer

Distroless images contain only the application and its runtime dependencies — no package manager, shell, or OS utilities — which dramatically reduces the attack surface and the number of exploitable CVEs. Because there is no shell or package manager, attackers who gain code execution have far fewer tools to pivot or escalate with. This makes distroless the strongest choice when the explicit goal is minimizing vulnerabilities in a container image.

Exam trap

The trap here is assuming 'smaller image = fewer vulnerabilities' and picking Alpine, when the exam is specifically testing that distroless removes even the shell and package manager, which Alpine retains.

How to eliminate wrong answers

Option A is wrong because a full distribution image like Ubuntu ships hundreds of packages (apt, bash, coreutils, systemd components) that are not needed at runtime and each contributes CVEs and attack surface. Option B is wrong because Alpine, while small, still includes a shell (BusyBox ash), a package manager (apk), and musl libc, so it retains more attack surface than distroless and has historically had its own CVE stream. Option D is wrong because the 'latest' tag is a mutable pointer that provides no version pinning or reproducibility, and official images are typically full distributions — it maximizes both supply-chain risk and vulnerability count rather than minimizing them.

66
MCQmedium

A DevSecOps team runs workloads on a managed Kubernetes service. The security policy states that no pod may run as the root user, that containers must not mount the host filesystem, and that privilege escalation must be blocked. The team wants a control that evaluates pod specifications at admission time and rejects non-compliant pods before they are scheduled, without modifying application code. Which mechanism should the team implement?

A.A runtime security agent that scans running containers and sends alerts when it detects root processes
B.A PodSecurityPolicy object bound to the service account used by the workloads
C.A validating admission webhook or a Pod Security Admission configuration with the restricted profile enforced
D.A network policy that denies ingress to the pods from all namespaces except the application namespace
AnswerC

Pod Security Admission is the built-in successor to PodSecurityPolicy and enforces the restricted profile, which requires non-root execution, disallows host filesystem mounts, and blocks privilege escalation. A validating admission webhook can enforce custom policies with greater flexibility. Both evaluate pod specifications at admission time and reject non-compliant pods before scheduling, without requiring application code changes.

Why this answer

The requirement is admission-time rejection of pods that run as root, mount the host filesystem, or allow privilege escalation. Pod Security Admission with the restricted profile, or a validating admission webhook, evaluates pod specifications before scheduling and rejects non-compliant pods without code changes. Network policies and runtime agents address different layers and cannot prevent the pods from being admitted.

Exam trap

The trap here is selecting PodSecurityPolicy, which is removed in current Kubernetes, or a runtime tool, which detects rather than prevents non-compliant pods.

67
MCQmedium

A healthcare organization runs a regulated workload on a public cloud. The security team must ensure that data stored in object storage remains unreadable to the cloud provider's staff even if they have physical access to the storage media. Which approach best meets this requirement?

A.Enable server-side encryption with provider-managed keys
B.Rely on transport-layer encryption using TLS for all uploads and downloads
C.Enable server-side encryption with customer-provided keys that the provider does not retain
D.Encrypt data client-side before upload and retain sole custody of the keys
AnswerD

Client-side encryption performed before the data leaves the customer's environment ensures the provider only ever receives ciphertext. Because the customer never shares the keys, provider personnel cannot decrypt the objects even with full physical access to storage media. This is the classic approach for meeting requirements that the cloud provider itself must be unable to read regulated data, and it directly satisfies the stated constraint.

Why this answer

When the requirement is that the cloud provider itself must be unable to read the data, the customer must control encryption end to end. Encrypting client-side before upload and keeping keys outside the provider's reach guarantees that only ciphertext ever reaches provider infrastructure. Server-side options, whether provider-managed or customer-provided per request, still involve provider systems handling keys or plaintext at some point.

Exam trap

The trap here is treating any server-side encryption option as equivalent to customer-controlled encryption, when only client-side encryption with customer-held keys removes the provider from the trust boundary.

68
MCQhard

In a cloud environment using KVM, a security auditor wants to ensure that a tenant VM cannot access the memory of another tenant VM on the same physical host. Which resource isolation mechanism is specifically designed to prevent such memory access?

A.Seccomp profiles
B.CPU pinning
C.Extended Page Tables (EPT)
D.IOMMU
AnswerC

Extended Page Tables provide hardware-assisted second-level address translation, giving each guest VM its own nested page tables managed by the hypervisor. This isolates guest physical memory so one tenant VM cannot map or read another's memory, directly satisfying the auditor's cross-tenant isolation requirement.

Why this answer

Extended Page Tables (EPT) is a hardware virtualization feature (Intel VT-x) that provides second-level address translation, isolating guest physical memory from host physical memory. It ensures that a VM's memory accesses are translated through nested page tables controlled by the hypervisor, preventing one tenant VM from accessing another tenant's memory. EPT, along with AMD's Nested Page Tables (NPT), is specifically designed for memory isolation in virtualized environments.

Exam trap

The trap here is confusing memory isolation mechanisms (EPT) with syscall filtering (Seccomp) or device isolation (IOMMU), leading candidates to pick IOMMU because it also sounds like an isolation technology.

How to eliminate wrong answers

Option A is wrong because Seccomp profiles restrict the system calls a process can make, which is a syscall-level sandboxing mechanism, not a memory isolation technology. Option B is wrong because CPU pinning binds a virtual CPU to a physical core for performance predictability, not for memory isolation between tenants. Option D is wrong because IOMMU (Input-Output Memory Management Unit) isolates device DMA access to memory, protecting against rogue devices, but it does not directly prevent one VM from reading another VM's memory through normal CPU memory accesses.

69
MCQhard

A cloud architect is designing VPC connectivity for a global organization with multiple AWS accounts. They need a central hub for connecting many VPCs together, supporting transitive routing. Which service should they use?

A.Private Link
B.Transit Gateway
C.VPN Connection
D.VPC Peering
AnswerB

Transit Gateway acts as a regional hub attaching many VPCs and on-premises networks, with transitive routing between attachments. That satisfies the central-hub and transitive-routing constraints, unlike VPC peering, which is non-transitive and requires a mesh of individual connections.

Why this answer

AWS Transit Gateway acts as a central hub that connects multiple VPCs and on-premises networks, supporting transitive routing between all attached VPCs. It simplifies network architecture by eliminating the need for complex full-mesh VPC peering and allows scalable, hub-and-spoke connectivity. For a global organization with many VPCs across accounts, Transit Gateway is the designed solution.

Exam trap

CCSP often tests the confusion between VPC Peering (non-transitive, one-to-one) and Transit Gateway (transitive, hub-and-spoke), leading candidates to pick VPC Peering for scalable multi-VPC connectivity.

How to eliminate wrong answers

Option A is wrong because AWS PrivateLink provides private connectivity to services, not a hub for connecting many VPCs with transitive routing; it is used for service-level access, not network-level peering. Option C is wrong because a VPN Connection connects on-premises networks to a single VPC, not multiple VPCs with transitive routing. Option D is wrong because VPC Peering is non-transitive and requires a full mesh for many-to-many connectivity, which does not scale for a global organization with numerous VPCs.

70
MCQmedium

A security engineer is reviewing container image security. Which of the following practices best ensures that a container image has not been tampered with and originates from a trusted source?

A.Scanning the image with Trivy for CVEs
B.Using a minimal base image like Alpine
C.Setting the image tag to :latest
D.Signing the image with Cosign and verifying it at deployment
AnswerD

Cosign applies a cryptographic signature tied to the publisher's private key, and verification at deployment rejects any image whose digest or signature fails validation. This satisfies the tamper-evidence and trusted-origin constraint, since unsigned or altered images cannot pass admission.

Why this answer

Signing a container image with Cosign and verifying it at deployment ensures integrity and provenance by cryptographically binding the image to a trusted signer. Cosign uses public-key cryptography to sign the image digest, and verification at deployment (e.g., via admission controllers) ensures only signed images run. This directly addresses tampering and trusted source requirements.

Exam trap

The trap is equating vulnerability scanning or using minimal base images with integrity verification; only cryptographic signing and verification provide tamper-evidence and provenance.

How to eliminate wrong answers

Option A is wrong because scanning with Trivy detects known vulnerabilities (CVEs) but does not verify image integrity or origin; a tampered image could still pass a vulnerability scan. Option B is wrong because using a minimal base image like Alpine reduces attack surface but does not provide any cryptographic assurance of integrity or source. Option C is wrong because setting the image tag to :latest is an anti-pattern that can lead to unpredictable deployments and does not ensure integrity; tags are mutable and can be overwritten.

71
Multi-Selecthard

A cloud security architect is hardening the metadata service on a fleet of EC2 instances that host a customer-facing web application. The team wants to reduce the risk of server-side request forgery leading to credential theft, while keeping the application's legitimate ability to retrieve instance role credentials. Which TWO measures should the architect implement? (Choose two.)

Select 2 answers
A.Set the instance metadata service hop limit to 1 so responses cannot traverse additional network hops.
B.Enable AWS CloudTrail data events on the S3 bucket that stores application logs.
C.Attach an IAM role with a permissions boundary that denies all actions except those the application needs.
D.Enforce IMDSv2 by setting the instance metadata options to require tokens (HttpTokens: required).
E.Disable the instance metadata service entirely on all web application instances.
AnswersA, D

A hop limit of 1 prevents metadata responses from being forwarded beyond the instance itself, defeating the common attack pattern where a proxy or container layer relays the request. Combined with token enforcement it closes both the request-forging and the forwarding path, and it does not interfere with direct metadata calls made by the application on the instance.

Why this answer

Requiring IMDSv2 forces token-based requests that SSRF payloads generally cannot produce, and a hop limit of 1 stops metadata responses from being relayed through proxies or container layers. Together they harden the endpoint while preserving legitimate role credential retrieval. The remaining choices either fail to block the retrieval path or break required functionality.

Exam trap

The trap here is believing that tightening the IAM role's permissions neutralizes SSRF credential theft, when the exposure is the metadata endpoint itself and the credentials remain retrievable regardless of how narrowly scoped they are.

72
MCQeasy

A cloud security architect is designing a multi-tenant virtualized environment. Which type of hypervisor is considered most secure for cloud deployments due to its reduced attack surface and direct hardware control?

A.Type 1 bare-metal hypervisor
B.Type 2 hosted hypervisor
C.Emulated hypervisor (e.g., QEMU without KVM)
D.Container runtime (e.g., Docker)
AnswerA

A Type 1 hypervisor runs directly on the host hardware, so it exposes no underlying general-purpose OS for a guest escape to target. That smaller attack surface, plus direct hardware control, satisfies the multi-tenant isolation requirement where a compromised tenant must not reach others or the platform.

Why this answer

A Type 1 bare-metal hypervisor runs directly on the host's hardware, controlling hardware resources and managing guest VMs without an underlying operating system. This architecture reduces the attack surface because there is no general-purpose OS to exploit, and it provides direct hardware control for performance and security. It is considered the most secure for cloud deployments.

Exam trap

The trap is assuming that containers or Type 2 hypervisors provide equivalent security to Type 1 hypervisors, when the additional layers or shared kernel increase risk.

How to eliminate wrong answers

Option B is wrong because a Type 2 hosted hypervisor runs as an application on top of a host OS, which adds an additional layer (the host OS) that increases the attack surface and potential for privilege escalation. Option C is wrong because an emulated hypervisor like QEMU without KVM uses software emulation, which is slower and more complex, often introducing more vulnerabilities; it does not provide direct hardware control. Option D is wrong because a container runtime like Docker shares the host OS kernel and does not provide the same level of isolation as a Type 1 hypervisor; containers are not virtual machines and are more susceptible to kernel exploits.

73
MCQmedium

A company stores sensitive backups in cloud object storage. The security policy requires that backups be recoverable even if the primary cloud region suffers a catastrophic outage, and that the backup data remain encrypted with keys the company controls throughout replication. Which configuration best satisfies both requirements?

A.Single-region storage with versioning and object lock enabled
B.Cross-region replication with client-side encryption using keys held only in the source region
C.Cross-region replication with customer-managed keys replicated to the destination region
D.Cross-region replication with provider-managed encryption keys in both regions
AnswerC

Replicating objects to a second region protects against a regional outage, and using customer-managed keys that are also replicated to the destination region ensures the company retains cryptographic control and can decrypt in the secondary region without provider key custody. This combination satisfies both durability and key ownership requirements, and it is the standard pattern for regulated backup architectures.

Why this answer

The scenario imposes two independent requirements: survive a regional outage and keep encryption keys under company control throughout replication. Cross-region replication satisfies the first, and customer-managed keys replicated to the destination region satisfy the second. Client-side encryption with keys confined to the source region fails because a regional outage would strand the keys, leaving replicated ciphertext unrecoverable.

Exam trap

The trap here is focusing only on where the ciphertext is replicated while forgetting that the decryption keys must also survive the same regional failure.

74
MCQmedium

A cloud security engineer is configuring an Amazon S3 bucket that must store sensitive financial data. The requirement is that all data must be encrypted at rest with keys that the organization controls and can rotate, and that access to the keys must be auditable and separable from the data access permissions. Which S3 encryption option BEST meets these requirements?

A.SSE-C where the customer provides the encryption key with each request, and the key is stored in AWS Secrets Manager for automatic retrieval.
B.SSE-KMS with a customer managed key in AWS KMS, with a key policy that grants decrypt permissions only to specific roles and enables automatic key rotation.
C.SSE-S3 with default bucket encryption enabled and S3 Block Public Access turned on.
D.Client-side encryption using the AWS Encryption SDK with a master key stored in an on-premises HSM, and uploading the encrypted objects to S3.
AnswerB

SSE-KMS with a customer managed key gives the organization control over the key, supports automatic rotation, and allows a key policy that is separate from S3 bucket policies. AWS CloudTrail logs all KMS key usage, providing auditability, and access to keys can be granted independently of access to the S3 data.

Why this answer

The requirement calls for customer-controlled keys, rotation, and auditable, separable key access. SSE-KMS with a customer managed key in AWS KMS satisfies all three: the organization creates and controls the key, can enable automatic rotation, and uses key policies and IAM to separate key access from S3 data access. CloudTrail logs every KMS operation, providing the needed audit trail.

Other options either use AWS-managed keys or shift key management outside AWS, failing at least one requirement.

Exam trap

The trap here is choosing SSE-C or client-side encryption because they seem to offer more control, while overlooking that SSE-KMS with a customer managed key already provides control, rotation, and integrated auditability without the operational burden.

75
MCQmedium

A security analyst is configuring an API Gateway for a cloud application. The application must handle high traffic and prevent abuse from a single client. Which feature should the analyst enable to limit the number of requests from a client within a specified time window?

A.Rate limiting
B.TLS enforcement
C.Web Application Firewall (WAF) integration
D.API key authentication
AnswerA

Rate limiting caps the number of requests a client may send within a defined time window, returning throttling responses once the threshold is exceeded. This directly satisfies the requirement to prevent a single client from abusing the API during high traffic.

Why this answer

Rate limiting is the API Gateway feature that restricts the number of requests a client can make within a specified time window (e.g., 1000 requests per minute). It directly addresses the requirement to handle high traffic and prevent abuse from a single client by throttling or rejecting excess requests. This protects backend services from being overwhelmed and ensures fair usage.

Exam trap

The trap is confusing authentication (API keys) or encryption (TLS) with abuse prevention — candidates may think that requiring an API key stops abuse, but the exam tests whether you know that only rate limiting enforces request quotas per client.

How to eliminate wrong answers

Option B is wrong because TLS enforcement ensures encrypted communication between clients and the API Gateway; it does not limit request volume or prevent abuse from a single client. Option C is wrong because WAF integration protects against web application attacks (SQL injection, XSS) by filtering malicious payloads; it does not enforce request quotas per client. Option D is wrong because API key authentication identifies and authenticates clients but does not limit how many requests they can make — a valid API key can still be used for abuse unless rate limiting is also applied.

Page 1 of 2 · 111 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Cloud Platform and Infrastructure Security questions.