Courseiva

CCNA Cloud Platform and Infrastructure Security Questions

36 of 111 questions · Page 2/2 · Cloud Platform and Infrastructure Security · Answers revealed

76
Multi-Selectmedium

A cloud security engineer is hardening container runtime environments. Which TWO of the following are effective measures to prevent container escape?

Select 2 answers
A.Using the latest kernel version
B.Mounting the host filesystem as read-only
C.Running containers in privileged mode
D.Dropping all Linux capabilities except those required
E.Applying Seccomp profiles
AnswersD, E

Dropping unneeded Linux capabilities directly shrinks the kernel attack surface available inside a container, satisfying the stem's requirement to prevent escape. Without privileges such as CAP_SYS_ADMIN, a compromised process cannot mount filesystems, load modules or manipulate namespaces, so breakout techniques that depend on elevated capabilities fail.

Why this answer

Option D is correct because dropping all Linux capabilities except those strictly required follows the principle of least privilege and removes the powerful capabilities (such as CAP_SYS_ADMIN, CAP_NET_ADMIN, or CAP_SYS_PTRACE) that container-escape exploits typically abuse to break out of the namespace and interact with the host. Option E is correct because Seccomp profiles restrict the set of system calls a container process can invoke, blocking dangerous syscalls (e.g., ptrace, mount, unshare, keyctl) that are commonly leveraged in kernel-exploit-based escapes. Option A is not a preventive control for container escape: keeping the kernel patched reduces known vulnerabilities but does not by itself constrain a container's privileges or syscall surface.

Option B is not effective as stated because mounting the host filesystem read-only does not prevent escape — an attacker can still gain host access and then remount or exploit writable paths; the real mitigation is not exposing the host filesystem to the container at all. Option C is incorrect because privileged mode disables the very isolation mechanisms (capabilities, seccomp, AppArmor/SELinux, device cgroup) that prevent escape, making it the opposite of a hardening measure.

Exam trap

CCSP often tests whether candidates recognize that 'privileged mode' is a vulnerability, not a mitigation, and that generic practices like 'latest kernel' or 'read-only host mount' are distractors that sound secure but do not address container escape specifically.

77
MCQeasy

A cloud security professional is concerned about VM escape attacks. Which mitigation is most effective?

A.Encryption of VM disks
B.Regular patching of the hypervisor
C.Use of Type 2 hypervisors
D.Network segmentation between VMs
AnswerB

VM escape exploits target hypervisor vulnerabilities, so applying hypervisor patches closes the flaws an attacker would use to break out of a guest VM. This directly addresses the escape vector in a multi-tenant environment, where a single unpatched hypervisor flaw could expose every co-resident tenant.

Why this answer

VM escape attacks exploit vulnerabilities in the hypervisor to break out of a guest VM and access the host or other guests. Regularly patching the hypervisor closes known vulnerabilities (e.g., Xen, KVM, VMware ESXi CVEs) that attackers use to escape, making it the most direct and effective mitigation. Since the hypervisor is the isolation boundary, keeping it current is foundational to VM security.

Exam trap

CCSP often tests whether candidates confuse data-at-rest protections (disk encryption) or network controls (segmentation) with hypervisor-layer isolation — the trap is picking a control that addresses a different threat model than VM escape.

How to eliminate wrong answers

Option A is wrong because encrypting VM disks protects data at rest and does nothing to prevent a running VM from escaping to the host. Option C is wrong because Type 2 hypervisors (hosted, e.g., VirtualBox, VMware Workstation) run on top of a general-purpose OS and generally have a larger attack surface than Type 1 (bare-metal) hypervisors, so they are not a more effective mitigation. Option D is wrong because network segmentation between VMs limits lateral movement after a compromise but does not prevent the escape itself, which occurs at the hypervisor layer, not the network layer.

78
MCQmedium

An organization uses Azure Functions and needs to ensure that the function can securely access a database in a private VNet. What is the recommended approach?

A.Place the function in the same VNet as the database without any additional configuration
B.Use a VPN connection from the function to the database VNet
C.Enable VNet integration for the function app and configure the function to use the private IP of the database
D.Store database credentials in environment variables and use a public endpoint with IP whitelisting
AnswerC

VNet integration routes the function app's outbound traffic into the delegated subnet, letting it reach the database's private IP directly. This satisfies the stem's requirement for secure private access without exposing the database publicly. Combined with private endpoints or service endpoints, traffic stays on the Azure backbone, avoiding public internet exposure entirely.

Why this answer

VNet integration allows Azure Functions to access resources in a virtual network without exposing them to the internet, using a private IP.

79
MCQeasy

A financial services company is migrating its cardholder data environment to a public cloud IaaS platform. The security team must determine which controls remain the customer's responsibility under the shared responsibility model. Which of the following is the customer's responsibility in this IaaS deployment?

A.Maintaining the physical security controls of the data center housing the hosts
B.Managing the redundancy of the physical network switches that interconnect racks
C.Patching the guest operating system and its installed applications
D.Applying firmware and microcode updates to the underlying hypervisor hosts
AnswerC

In IaaS the provider secures the physical hosts, hypervisor, and network fabric, while the customer retains full control and responsibility for the guest operating system, middleware, and applications running on top of it. Patching the guest OS in the cardholder environment is therefore squarely a customer duty, and auditors will expect documented patch management evidence for those instances.

Why this answer

Under the shared responsibility model for IaaS, the provider owns security of the cloud, including facilities, hardware, and the hypervisor, while the customer owns security in the cloud. That includes the guest operating system, runtime, applications, and data. Because the question concerns a cardholder data environment, the customer must demonstrate patch management for the guest OS and applications as part of PCI DSS compliance obligations.

Exam trap

The trap here is assuming that because the provider manages the platform, it also patches the guest operating system, when in IaaS the customer always owns everything from the OS upward.

80
MCQhard

A cloud architect is designing a multi-tenant environment. To ensure that a tenant's virtual machine cannot access another tenant's memory, which resource isolation technique should be enforced at the hypervisor level?

A.IOMMU for device isolation
B.Memory isolation via hardware-enforced page tables
C.CPU pinning
D.Network segmentation with VLANs
AnswerB

Hardware-enforced page tables give each tenant VM its own second-level address translation, so the hypervisor maps guest physical addresses to distinct machine frames. This satisfies the stem's requirement that one tenant's VM cannot read another tenant's memory, since no shared mapping exists.

Why this answer

Memory isolation via hardware-enforced page tables (using CPU features like Intel VT-x EPT or AMD-V NPT) ensures that each VM's memory is mapped in separate address spaces managed by the hypervisor, so a guest cannot address or read another guest's physical memory. This is the fundamental hypervisor-level mechanism that enforces memory isolation between tenants. It directly addresses the requirement that one tenant's VM cannot access another's memory.

Exam trap

CCSP often tests whether candidates confuse device isolation (IOMMU), CPU scheduling (pinning), or network isolation (VLANs) with memory isolation — the trap is picking a control that addresses a different resource than the one named in the question.

How to eliminate wrong answers

Option A is wrong because IOMMU isolates device DMA access (preventing devices from writing to arbitrary memory), which is important for device passthrough but does not isolate guest memory from other guests. Option C is wrong because CPU pinning binds vCPUs to physical cores for performance and predictability, not for memory isolation. Option D is wrong because network segmentation with VLANs isolates network traffic, not memory, and operates at Layer 2 rather than the hypervisor memory layer.

81
Multi-Selecteasy

Which TWO of the following are characteristics of security groups compared to network ACLs in a cloud VPC? (Select two.)

Select 2 answers
A.Operate at the subnet level
B.Stateful – return traffic is automatically allowed
C.Stateless – each packet is evaluated independently
D.Support both allow and deny rules
E.Only allow rules can be specified
AnswersB, E

Security groups track connection state, so response traffic for an established flow is permitted automatically without a matching inbound rule. Network ACLs are stateless and require explicit rules for both directions, which is the axis of difference.

Why this answer

Option B is correct because security groups are stateful: when an inbound or outbound connection is permitted, the return traffic for that established flow is automatically allowed without needing a separate rule, unlike network ACLs which are stateless. Option E is correct because security groups only support allow rules; there is no way to create an explicit deny rule in a security group, whereas network ACLs support both allow and deny rules. Options A, C, and D describe network ACLs rather than security groups: network ACLs operate at the subnet level (A), are stateless and evaluate each packet independently (C), and support both allow and deny rules (D), so they do not belong as characteristics of security groups.

Exam trap

The trap here is confusing the stateful nature of security groups with the stateless nature of network ACLs, and forgetting that security groups only support allow rules.

82
MCQmedium

A healthcare company is migrating a legacy three-tier application to AWS. The security team must ensure that the database tier is reachable only from the application tier, that the rule follows the application instances automatically as they scale, and that no rule permits a broader source. Which mechanism should the team use?

A.A network ACL on the database subnet that allows inbound traffic only from the application subnet CIDR range.
B.A security group on the database instances that allows inbound traffic from the VPC CIDR range on the database port.
C.AWS PrivateLink endpoint policies that restrict which application-tier principals may open connections to the database.
D.A security group on the database instances whose inbound rule references the security group ID of the application tier.
AnswerD

Referencing the application tier's security group as the source means any instance that carries that group is automatically allowed, so newly launched application instances are covered without rule changes. No CIDR is involved, so nothing in the VPC outside the application tier can connect, and the rule is stateful, so return traffic needs no extra configuration.

Why this answer

A security group rule that names the application tier's security group as its source gives an identity-based, stateful permission that tracks instances through scaling events and excludes every other resource in the VPC. CIDR-based subnet filters and VPC-wide rules are broader than needed, and PrivateLink does not address intra-VPC tier isolation.

Exam trap

The trap here is choosing a CIDR-based rule because it feels more precise, when only a security-group reference automatically follows elastic instances and excludes unrelated workloads in the same subnet.

83
MCQhard

During a security review of a serverless application, you notice that a Lambda function's execution role has permissions to delete all S3 buckets in the account. What is the most appropriate remediation to align with the principle of least privilege?

A.Create a custom IAM role that grants only the necessary actions on a specific S3 bucket
B.Store S3 bucket names in environment variables instead of hardcoding
C.Attach the AWS managed policy 'AmazonS3ReadOnlyAccess'
D.Remove the Lambda function's VPC integration
AnswerA

A custom IAM role scoped to only the necessary actions on a specific S3 bucket removes the wildcard delete permissions, directly enforcing least privilege for the Lambda execution role instead of leaving account-wide destructive access.

Why this answer

The correct remediation is to replace the overly permissive execution role with a custom IAM role scoped to only the specific S3 actions and the specific bucket the Lambda function actually needs. This directly enforces least privilege by eliminating the wildcard delete permissions across all buckets. AWS IAM evaluates the policy attached to the Lambda execution role on every API call, so narrowing the Resource ARN and Action list constrains the blast radius if the function is compromised.

Exam trap

CCSP often tests least privilege by offering plausible-sounding but non-authorization fixes (environment variables, VPC changes) — candidates must recognize that only IAM policy scoping actually reduces permissions.

How to eliminate wrong answers

Option B is wrong because storing bucket names in environment variables is a configuration-hygiene improvement, not an authorization control — the role would still permit deleting all buckets regardless of how names are supplied. Option C is wrong because AmazonS3ReadOnlyAccess grants read-only access, which would break any legitimate write or delete operations the function needs and is not a least-privilege fit for its actual function. Option D is wrong because removing VPC integration affects network reachability, not IAM permissions — the role would still retain the excessive S3 delete rights.

84
MCQhard

During a supply chain security review, a team discovers that container images are not being verified at admission time. Which Kubernetes-native tool should be implemented to ensure only signed images are deployed?

A.NetworkPolicy
B.PodSecurityPolicy
C.Admission controller (e.g., Kyverno) with image signature verification
D.ResourceQuota
AnswerC

Kyverno runs as a validating admission controller, so it evaluates image signatures against trusted keys before the pod is admitted, rejecting unsigned images. This is Kubernetes-native and enforces the supply chain requirement at admission time, unlike runtime scanners or registry-only checks.

Why this answer

An admission controller like OPA Gatekeeper or Kyverno can enforce policies that verify image signatures before allowing pod creation.

85
MCQeasy

A cloud security team is reviewing container security practices. Which of the following is the most effective way to minimize the attack surface of a container image?

A.Using the latest version of a base image
B.Using a minimal base image such as distroless
C.Using the :latest tag to ensure freshness
D.Scanning the image for CVEs after deployment
AnswerB

Distroless images omit package managers, shells and other OS utilities, leaving only the application and its runtime dependencies. Fewer installed components mean fewer exploitable binaries and a smaller vulnerability surface, directly satisfying the requirement to minimise the image's attack surface.

Why this answer

Using a minimal base image such as distroless is the most effective way to reduce a container image's attack surface because it strips the package manager, shell, and unnecessary OS utilities, leaving only the application and its runtime dependencies. Fewer installed packages means fewer libraries that can contain exploitable CVEs, and the absence of a shell makes post-exploitation pivoting much harder. Distroless images, maintained by Google, include only the runtime (e.g., a JRE or Python interpreter) and the app itself.

Exam trap

CCSP often tests the difference between preventive minimization (distroless, multi-stage builds) and detective scanning — candidates pick 'scan after deployment' because it sounds thorough, but it does not reduce attack surface.

How to eliminate wrong answers

Option A is wrong because using the latest version of a base image does not minimize attack surface — a full OS base image still ships hundreds of packages, and 'latest' can introduce unexpected changes. Option C is wrong because the :latest tag is mutable and non-deterministic, breaking reproducibility and potentially pulling in new vulnerabilities; it also does not reduce the number of components. Option D is wrong because scanning for CVEs after deployment is a detective control, not a preventive reduction of attack surface — the vulnerable components are already running.

86
MCQmedium

A cloud security architect is designing a workload that must store encryption keys in a hardware security module (HSM) that is validated to FIPS 140-2 Level 3. The workload runs on a major public cloud provider. The architect wants to minimize operational overhead while ensuring the keys never leave the HSM boundary. Which cloud service model should the architect select?

A.A cloud provider's managed Hardware Security Module (HSM) service offering dedicated, tamper-resistant HSM appliances.
B.A software-based key management service that uses a shared, multi-tenant key store with encryption at rest.
C.A cloud provider's virtual private cloud (VPC) with a customer-managed encryption key stored in the provider's object storage.
D.An on-premises HSM connected to the cloud via a VPN tunnel, with keys replicated to the cloud provider's key vault.
AnswerA

A managed HSM service provides dedicated FIPS 140-2 Level 3 validated hardware, and the provider handles patching, scaling, and high availability. Keys are generated and stored inside the HSM boundary and cannot be exported in plaintext. This matches the requirement for minimal operational overhead while keeping keys within validated hardware, which is exactly what the architect needs.

Why this answer

The requirement is for a FIPS 140-2 Level 3 validated HSM with minimal operational overhead and keys that never leave the HSM. A managed HSM service provides dedicated, validated hardware while the provider handles maintenance and availability, satisfying both security and operational needs. Alternatives either lack hardware validation, export keys outside the boundary, or add unnecessary management burden.

Exam trap

The trap here is assuming that any encryption key store with encryption at rest meets the HSM requirement, when FIPS 140-2 Level 3 specifically demands tamper-resistant hardware.

87
MCQhard

A cloud provider offers a virtual private cloud (VPC) with a subnet that hosts a database. A security architect must ensure that only instances in a specific application security group can connect to the database on port 3306, and that no other traffic from the internet or other subnets can reach it. The architect is configuring security groups and network ACLs. Which combination of rules BEST achieves this?

A.Configure the database security group to allow inbound TCP 3306 from 0.0.0.0/0, and configure the network ACL to deny all traffic except from the application subnet CIDR.
B.Configure the database security group to allow inbound TCP 3306 from the application subnet CIDR, and configure the network ACL to allow inbound TCP 3306 from the application security group ID.
C.Configure the database security group to allow inbound TCP 3306 from the application security group ID, and leave the network ACL at its default allow-all state.
D.Configure the database security group to allow inbound TCP 3306 from the application security group ID, and configure the subnet's network ACL to allow inbound TCP 3306 from the application subnet CIDR only.
AnswerC

Security groups are stateful and support referencing other security groups as sources, so allowing inbound TCP 3306 from the application security group ID ensures only instances with that security group can connect. The default NACL allows all traffic, so it does not interfere. This combination precisely meets the requirement without over-permitting.

Why this answer

Security groups are stateful and can reference other security groups as sources, which is the most precise way to allow only instances with a specific application security group to reach the database. Network ACLs are stateless and subnet-level; they cannot reference security group IDs and should generally be left at default allow unless additional subnet-level controls are needed. Allowing the application security group ID on the database security group meets the requirement exactly.

Exam trap

The trap here is assuming network ACLs can reference security group IDs or that subnet CIDR is equivalent to security group membership, when only security groups support security group references and stateful evaluation.

88
MCQeasy

A cloud security administrator is responsible for managing access to a cloud management console. The organization wants to enforce multi-factor authentication (MFA) for all human users and ensure that programmatic access uses short-lived credentials instead of long-term access keys. Which approach BEST aligns with these requirements?

A.Use an identity provider with SAML 2.0 federation for console access with MFA enforced, and use IAM roles with temporary credentials for programmatic access via AWS STS.
B.Create a single shared IAM user for all administrators with MFA enabled and distribute the access keys securely to the team.
C.Create IAM users with long-term access keys and attach an IAM policy that requires MFA for console access only.
D.Store IAM user access keys in AWS Secrets Manager and rotate them every 90 days, while enabling MFA for the root account only.
AnswerA

SAML 2.0 federation with an identity provider enforces MFA at the identity provider and issues temporary console sessions. For programmatic access, assuming IAM roles via AWS STS provides short-lived credentials that expire automatically. This combination meets both requirements without long-term keys.

Why this answer

Enforcing MFA for human users is best achieved through federation with an identity provider that applies MFA, such as SAML 2.0, which issues temporary console sessions. For programmatic access, assuming IAM roles via AWS STS provides temporary credentials that rotate automatically, eliminating long-term access keys. Together these practices enforce MFA and short-lived credentials, aligning with cloud security best practices.

Exam trap

The trap here is thinking that rotating long-term access keys or enabling MFA only for the root account satisfies the requirement, when true compliance requires federation with MFA and temporary credentials for programmatic access.

89
MCQhard

A cloud security team wants to enforce that only signed container images are deployed in their Kubernetes cluster. Which admission controller can validate image signatures at deploy time?

A.HashiCorp Vault
B.Consul
C.Trivy
D.Kyverno
AnswerD

Kyverno is a Kubernetes admission controller that evaluates policies at deploy time, including verifying container image signatures against trusted keys. It satisfies the requirement to block unsigned images before they are admitted to the cluster.

Why this answer

Kyverno is a Kubernetes-native policy engine that functions as a validating admission controller. It can enforce policies that check container image signatures (e.g., using Cosign) at deploy time by validating the image's signature against a public key before allowing the pod to be created. This directly satisfies the requirement to only allow signed images.

Exam trap

CCSP often tests the confusion between security tools that scan images (like Trivy) and those that enforce policies at admission time (like Kyverno), so candidates must distinguish between detection and enforcement.

How to eliminate wrong answers

Option A is wrong because HashiCorp Vault is a secrets management tool, not a Kubernetes admission controller; it cannot validate image signatures at deploy time. Option B is wrong because Consul is a service mesh and service discovery tool, not an admission controller for image signature validation. Option C is wrong because Trivy is a vulnerability scanner for container images, not an admission controller; it can scan images but does not enforce policies during deployment.

90
MCQmedium

A cloud security team needs to ensure that an Amazon EC2 instance hosting a regulated workload cannot communicate with the public internet, but the instance must still be able to download OS patches from an internal repository and retrieve secrets from AWS Secrets Manager. The workload runs in a private subnet with no NAT gateway or internet gateway route. Which combination of configurations will meet these requirements with the LEAST operational overhead?

A.Attach an internet gateway to the VPC and use a security group that allows only outbound HTTPS to the patch server and Secrets Manager endpoints.
B.Place the instance in a public subnet and use an AWS Network Firewall policy to block all outbound traffic except the patch server and Secrets Manager IP ranges.
C.Deploy a NAT gateway in a public subnet and update the private subnet route table to direct 0.0.0.0/0 through the NAT gateway, then restrict outbound traffic using network ACLs.
D.Create VPC interface endpoints (AWS PrivateLink) for Secrets Manager and an S3 gateway endpoint for the patch repository, and associate the endpoints with the private subnet's route table and security group.
AnswerD

Interface endpoints for Secrets Manager and a gateway endpoint for S3 keep traffic on the AWS private network without any internet gateway or NAT device. Associating the endpoints with the subnet route table and allowing the endpoint security group to accept traffic from the instance satisfies both patch retrieval and secret access while eliminating public exposure. This is the lowest-overhead, most auditable design.

Why this answer

VPC interface endpoints (AWS PrivateLink) and S3 gateway endpoints let resources in private subnets reach AWS services entirely over the AWS private network, with no internet gateway, NAT, or public IP required. This satisfies the no-internet constraint, supports both patch retrieval and secret access, and requires minimal ongoing operational effort compared to firewall or NAT-based designs.

Exam trap

The trap here is assuming that a NAT gateway or restrictive firewall rules satisfy a 'no public internet' requirement, when in fact any route to an internet gateway or NAT device still constitutes public internet connectivity.

91
MCQmedium

A cloud operations team runs a web tier on 40 Amazon EC2 instances behind an Application Load Balancer. Auditors require that administrators never hold long-lived SSH keys and that every login to an instance is logged with the identity of the human who initiated it. The team already uses an external SAML 2.0 identity provider for console access. Which approach BEST satisfies the auditors' requirements?

A.Deploy a bastion host with SSH certificate authority signing and rotate host certificates every 24 hours.
B.Enable AWS Systems Manager Session Manager with the instances managed by SSM Agent, and grant access through the federated IAM role.
C.Store a shared PEM key pair in AWS Secrets Manager and issue it to administrators through a break-glass runbook.
D.Move the instances into a private subnet, restrict port 22 to the corporate CIDR range, and enable VPC Flow Logs on the subnet.
AnswerB

Session Manager tunnels interactive shell sessions through the SSM service without opening inbound ports or distributing key pairs. Because authorization flows through IAM roles assumed from the SAML identity provider, each session is recorded in CloudTrail and Session Manager session history with the originating federated principal, giving auditors per-human attribution and eliminating long-lived SSH credentials entirely.

Why this answer

Session Manager provides keyless, auditable interactive access that inherits the federated IAM identity, so every session is attributable to a named administrator and no standing SSH keys exist. The other designs either retain long-lived key material or produce only network-level telemetry that cannot identify the human operator, which fails the auditors' attribution and key-elimination requirements.

Exam trap

The trap here is assuming that tightening network access or rotating SSH keys satisfies an identity-attribution requirement, when the auditors actually demanded elimination of long-lived credentials tied to a federated human identity.

92
MCQhard

A financial services firm runs a regulated workload on a public cloud. Auditors require evidence that the cloud provider's physical security controls meet the firm's requirements. Which artifact provides the MOST direct evidence?

A.The cloud provider's SOC 2 Type II report covering the relevant data center and service scope.
B.A penetration test report commissioned by the cloud provider for its data centers.
C.The cloud provider's marketing security whitepaper describing data center protections.
D.The provider's ISO 27001 certificate displayed on its trust portal.
AnswerA

A SOC 2 Type II report includes an independent auditor's opinion on the design and operating effectiveness of controls, including physical security, over a period. It provides direct, time-bound evidence that the provider's controls were tested, which is exactly what the firm's auditors need.

Why this answer

A SOC 2 Type II report gives independent, period-based assurance over control design and operating effectiveness, including physical security, which directly satisfies auditor evidence requirements. Whitepapers, ISO certificates, and penetration test reports either lack independent testing, lack control-effectiveness detail, or address different scopes.

Exam trap

The trap here is equating any certification or security document with audit-grade evidence, when only a Type II report demonstrates that controls operated effectively over a defined period.

93
MCQhard

A security engineer is hardening a Kubernetes cluster that runs multi-tenant workloads. The team wants to ensure that a compromised pod cannot reach the cloud provider's instance metadata service to steal node credentials. Which control BEST addresses this?

A.Rotate node IAM credentials every 24 hours using the cloud provider's rotation service.
B.Enable PodSecurity admission with the restricted profile on all namespaces.
C.Use a service mesh with mutual TLS between all workloads in the cluster.
D.Enforce a NetworkPolicy that denies egress to the link-local address 169.254.169.254 from all pods.
AnswerD

The instance metadata service is reachable at 169.254.169.254 from the node network namespace, and pods on the node can often reach it. A default-deny egress NetworkPolicy targeting that link-local address blocks pods from retrieving node IAM credentials, directly mitigating the credential theft scenario.

Why this answer

Blocking egress to 169.254.169.254 with a NetworkPolicy directly prevents pods from reaching the instance metadata service, which is the specific vector for stealing node credentials. PodSecurity, credential rotation, and service mesh mTLS address different risks and do not stop a pod from querying the metadata endpoint.

Exam trap

The trap here is assuming that workload hardening controls such as PodSecurity or mTLS also restrict network paths to the metadata service, when only explicit egress filtering addresses that link-local access.

94
MCQeasy

A security engineer is reviewing container security practices. Which tool is specifically designed to scan container images for Common Vulnerabilities and Exposures (CVEs)?

A.Kubernetes RBAC
B.Trivy
C.Seccomp
D.OPA Gatekeeper
AnswerB

Trivy is an open-source scanner built specifically to inspect container images (and filesystems, repositories) for known CVEs in OS packages and language dependencies. It satisfies the stem's requirement for a tool designed for image vulnerability scanning, unlike general-purpose registries or orchestrators.

Why this answer

Trivy is an open-source vulnerability scanner specifically designed to scan container images, filesystems, and Git repositories for CVEs and misconfigurations. It integrates directly with container registries and CI/CD pipelines, making it the go-to tool for image security in cloud-native environments. Unlike the other options, Trivy's core function is vulnerability detection, not access control or runtime enforcement.

Exam trap

CCSP often tests the confusion between security tools that operate at different layers: candidates may mistake runtime security tools (Seccomp) or policy engines (OPA Gatekeeper) for vulnerability scanners, overlooking that Trivy is purpose-built for CVE detection in images.

How to eliminate wrong answers

Option A is wrong because Kubernetes RBAC is an authorization mechanism that controls access to Kubernetes API resources, not a vulnerability scanner. Option C is wrong because Seccomp is a Linux kernel feature used to restrict system calls made by a process, providing runtime sandboxing, not CVE scanning. Option D is wrong because OPA Gatekeeper is a policy enforcement tool that uses Open Policy Agent to validate and mutate Kubernetes resources based on custom policies, not a vulnerability scanner.

95
MCQhard

A company uses AWS and needs to allow a Lambda function in a VPC to access an S3 bucket without traversing the internet. Which solution meets this requirement securely?

A.Configure a NAT gateway in the VPC and route traffic through it
B.Create a VPC endpoint for S3 and attach it to the Lambda's VPC
C.Use VPC peering to connect to the S3 bucket's VPC
D.Assign a public IP to the Lambda and use an internet gateway
AnswerB

A VPC endpoint for S3 routes traffic privately through the AWS network to the bucket, so the Lambda function never traverses the internet. This satisfies the no-internet constraint while keeping access controlled by endpoint and bucket policies rather than public exposure.

Why this answer

A VPC endpoint for S3 (gateway endpoint) allows resources in a VPC, including Lambda functions, to reach S3 privately without traversing the internet, NAT, or an internet gateway. Traffic stays on the AWS backbone and can be controlled with endpoint policies.

Exam trap

CCSP often tests whether candidates confuse NAT gateway (internet-bound) with VPC endpoints (private AWS service access) and mistakenly try to peer with an AWS-managed service VPC.

How to eliminate wrong answers

Option A is wrong because a NAT gateway routes traffic to the internet, which violates the requirement to avoid internet traversal and adds cost. Option C is wrong because VPC peering connects two VPCs, but S3 is not in a customer VPC — it is an AWS service, so peering does not apply. Option D is wrong because assigning a public IP and using an internet gateway sends traffic over the public internet, which is insecure and unnecessary.

96
MCQhard

During a security assessment of a Kubernetes cluster, you discover that a container is running as root with privileged mode enabled. Which of the following is the most critical risk associated with this configuration?

A.Network policy bypass allowing unauthorized pod communication
B.Potential for container escape to the host OS
C.Increased memory consumption due to lack of resource limits
D.Inability to mount volumes for persistent storage
AnswerB

Privileged mode grants the container broad Linux capabilities and direct access to host devices, so a compromise lets an attacker break out of the container namespace and execute code on the host OS, escalating from workload compromise to full node takeover.

Why this answer

Running a container as root with privileged mode enabled grants the container almost all the capabilities of the host's root user, including access to host devices and kernel features. This significantly increases the attack surface, making it easier for an attacker to exploit kernel vulnerabilities or misconfigurations to escape the container and gain control of the host OS. While other risks exist, container escape is the most critical because it compromises the entire node and potentially the whole cluster.

Exam trap

CCSP often tests the misconception that network policy bypass or resource limits are the primary risks of privileged containers, when the most critical risk is container escape leading to host compromise.

How to eliminate wrong answers

Option A is wrong because network policy bypass is a separate concern related to network policies and CNI plugins, not directly caused by privileged mode; privileged mode primarily affects host access, not network segmentation. Option C is wrong because increased memory consumption is due to lack of resource limits, which is unrelated to running as root or privileged mode. Option D is wrong because inability to mount volumes is typically due to missing volume mounts or permissions, not privileged mode; in fact, privileged mode often allows more mounting capabilities, not less.

97
Multi-Selecthard

A DevSecOps team is implementing a secure container supply chain. Which THREE practices should they adopt to ensure image integrity and trust from build to deployment?

Select 3 answers
A.Signing container images with Cosign
B.Storing images in a private registry without scanning
C.Using admission controller (e.g., Kyverno) to verify signatures
D.Allowing any image with a :latest tag
E.Scanning images for vulnerabilities using Trivy
AnswersA, C, E

Cosign attaches cryptographic signatures to container images at build time, binding an image digest to a trusted signing identity. This gives downstream admission checks verifiable provenance, satisfying the integrity and trust requirement across the supply chain.

Why this answer

Option A is correct because Cosign (part of the Sigstore project) cryptographically signs container images using keyless or key-based signatures, producing a verifiable signature stored in the OCI registry that establishes provenance and integrity from build time. Option C is correct because an admission controller such as Kyverno (or OPA Gatekeeper) enforces policy at deploy time by verifying Cosign signatures before allowing a pod to be admitted, ensuring only trusted, signed images run in the cluster. Option E is correct because Trivy scans image layers against vulnerability databases (e.g., CVE feeds) and can fail CI/CD pipelines on critical findings, catching known flaws before an image is promoted.

Option B is not appropriate because a private registry alone provides no integrity verification, and skipping scanning removes a key detection control. Option D is wrong because the mutable :latest tag offers no immutability or traceability, undermining supply-chain trust and reproducibility.

98
MCQeasy

A cloud security professional is evaluating container runtime security. Which Linux capability should be dropped from a container to prevent it from loading kernel modules?

A.CAP_DAC_OVERRIDE
B.CAP_CHOWN
C.CAP_SYS_MODULE
D.CAP_NET_RAW
AnswerC

CAP_SYS_MODULE grants a process the ability to load and unload kernel modules via init_module and delete_module. Dropping it directly satisfies the stem's constraint: without this capability, the container cannot insert code into the host kernel, closing a critical container-escape and persistence vector.

Why this answer

CAP_SYS_MODULE is the Linux capability that permits a process to load and unload kernel modules via init_module() and delete_module() syscalls. Dropping it from a container's capability set prevents the containerized process from inserting malicious kernel code, which would otherwise be a direct path to host compromise. This is a standard hardening step in container security profiles (e.g., Docker's default seccomp/capability drop list).

Exam trap

The trap here is confusing file-system capabilities (DAC_OVERRIDE, CHOWN) with kernel-level capabilities (SYS_MODULE, SYS_ADMIN); candidates who don't memorize the capability-to-operation mapping often pick a familiar-sounding name.

How to eliminate wrong answers

Option A is wrong because CAP_DAC_OVERRIDE bypasses file read/write/execute permission checks — it has nothing to do with kernel module loading. Option B is wrong because CAP_CHOWN only allows changing file ownership (chown), which is unrelated to kernel module operations. Option D is wrong because CAP_NET_RAW permits use of raw sockets (e.g., for packet crafting/ping), not loading kernel modules.

99
MCQeasy

A cloud security engineer is configuring network security for a web application hosted on AWS. The application runs on EC2 instances behind an Application Load Balancer (ALB). The engineer needs to allow HTTP and HTTPS traffic from the internet to the ALB and restrict direct access to the EC2 instances. Which AWS service should be used to control inbound traffic to the ALB?

A.AWS Shield
B.Network ACLs
C.AWS WAF
D.Security groups
AnswerD

Security groups act as virtual firewalls for AWS resources, including ALBs and EC2 instances. They control inbound and outbound traffic at the instance level. For an ALB, you attach a security group to allow HTTP/HTTPS from the internet, and you can restrict EC2 instances to only accept traffic from the ALB's security group.

Why this answer

Security groups are stateful virtual firewalls that control inbound and outbound traffic for AWS resources such as ALBs and EC2 instances. They are the correct tool to allow HTTP/HTTPS to an ALB and to restrict EC2 instances to only accept traffic from the ALB. Network ACLs operate at the subnet level and are stateless, AWS WAF is for layer 7 protection, and AWS Shield is for DDoS mitigation, so none of these fulfill the basic network access control requirement.

Exam trap

The trap here is assuming that any security service (like WAF or Shield) can replace the fundamental network access control provided by security groups.

100
MCQmedium

A security engineer is concerned about a scenario where a malicious process inside a VM breaks out of the virtualized environment to compromise the hypervisor. What is this attack called and what is the primary mitigation?

A.VM sprawl; use resource limits
B.Side-channel attack; disable hyperthreading
C.Privilege escalation; enable SELinux inside VM
D.VM escape; regularly patch the hypervisor
AnswerD

VM escape occurs when a guest process exploits a hypervisor vulnerability to reach the host or other guests. Patching the hypervisor closes those flaws, which is the primary mitigation since the hypervisor is the isolation boundary being breached.

Why this answer

A VM escape is the class of attack where code running inside a guest VM exploits a vulnerability in the hypervisor (or virtual hardware emulation) to execute on the host. Because the hypervisor is the trust boundary, the primary mitigation is keeping it patched against known escape CVEs (e.g., VENOM, Xen XSA advisories). Regular hypervisor patching closes the specific flaws attackers leverage to break isolation.

Exam trap

The trap is conflating side-channel attacks (data leakage) with VM escape (isolation breach); both involve cross-VM concerns but only escape compromises the hypervisor itself.

How to eliminate wrong answers

Option A is wrong because VM sprawl refers to uncontrolled proliferation of VMs (a management/governance issue), and resource limits address DoS, not hypervisor breakout. Option B is wrong because side-channel attacks (e.g., Spectre, cache timing) leak data across VMs but are not the same as escaping to compromise the hypervisor, and disabling hyperthreading is only one partial mitigation. Option C is wrong because privilege escalation inside the guest OS (mitigated by SELinux) stays within the VM and does not cross the hypervisor boundary.

101
MCQmedium

A cloud security architect is designing a multi-tenant SaaS platform on AWS. The platform must ensure that each tenant's data is cryptographically isolated so that even a compromised application process cannot read another tenant's data. The architect plans to use AWS Key Management Service (KMS) with tenant-specific keys. Which of the following is the MOST critical security control to implement to achieve this isolation?

A.Store all tenant data in a single S3 bucket with a bucket policy that restricts access by tenant ID prefix.
B.Enable automatic key rotation for all KMS customer managed keys.
C.Use a separate KMS customer managed key per tenant and enforce strict IAM policies that limit each tenant's application role to only its own key.
D.Enable AWS CloudTrail logging for all KMS API calls and monitor for anomalous decrypt operations.
AnswerC

Using a distinct KMS key per tenant creates a cryptographic boundary: data encrypted under one key cannot be decrypted with another. Coupling this with least-privilege IAM policies ensures that a compromised process can only access its own tenant's key. This directly prevents cross-tenant data access, satisfying the isolation requirement.

Why this answer

The scenario requires cryptographic isolation so that a compromised process cannot read another tenant's data. Using a separate KMS customer managed key per tenant ensures that data is encrypted with distinct keys, and strict IAM policies limit each tenant's role to only its own key. This combination creates a strong boundary.

Other options are either hygiene practices or detective controls that do not prevent cross-tenant access.

Exam trap

The trap here is assuming that access control policies alone (like bucket policies or IAM) provide sufficient isolation, when cryptographic separation via distinct keys is required to prevent a compromised process from decrypting other tenants' data.

102
MCQhard

A healthcare cloud tenant must ensure that when a physical host is decommissioned, residual data in storage cannot be reconstructed. The provider offers self-encrypting drives. Which property most directly guarantees that cryptographic erasure is effective?

A.The media encryption key is wrapped by a key-encryption key that is destroyed on decommission
B.The drive firmware performs a multi-pass overwrite of all sectors
C.The drive is physically shredded at an approved destruction facility
D.The storage array keeps redundant copies of the data on mirrored volumes
AnswerA

Cryptographic erasure works by destroying the key that protects the media encryption key, rendering all ciphertext on the drive permanently undecryptable. If the key-encryption key is reliably destroyed and never escrowed elsewhere, the data becomes unrecoverable even if the platters are later read, which is the property the tenant needs contractually guaranteed.

Why this answer

Cryptographic erasure depends entirely on the irrecoverability of the key material protecting the drive. Only destroying the wrapping key that protects the media encryption key ensures that ciphertext on retired media can never be decrypted, which is precisely the guarantee a healthcare tenant needs for decommissioned storage.

Exam trap

The trap here is conflating physical sanitization methods like overwriting or shredding with cryptographic erasure, which is defined by destruction of the key rather than the data.

103
MCQmedium

A security architect is designing a container runtime security strategy. Which of the following controls is most effective at preventing a container from compromising the host kernel?

A.Seccomp profile
B.Read-only root filesystem
C.Resource limits (CPU/memory)
D.Image vulnerability scanning
AnswerA

Seccomp profiles filter the system calls a container may invoke, blocking the specific kernel interfaces an exploit needs to escalate to the host. This directly satisfies the stem's constraint of preventing host kernel compromise, since container escapes depend on unmediated syscalls rather than on network or filesystem configuration.

Why this answer

Seccomp (secure computing mode) profiles restrict the system calls a container can make to the host kernel, directly reducing the kernel attack surface. By filtering out dangerous syscalls, seccomp is the most effective control for preventing a compromised container from exploiting kernel vulnerabilities. It operates at the syscall boundary, which is the primary interface between containers and the host kernel.

Exam trap

CCSP often tests the misconception that filesystem or resource controls provide kernel-level protection, when in fact only syscall-filtering mechanisms like seccomp directly reduce the kernel attack surface from a container.

How to eliminate wrong answers

Option B (Read-only root filesystem) is wrong because it prevents filesystem writes within the container but does nothing to restrict syscall access to the kernel — an attacker can still invoke dangerous syscalls. Option C (Resource limits) is wrong because CPU/memory limits only prevent resource exhaustion (DoS) and have no bearing on kernel exploitation via syscalls. Option D (Image vulnerability scanning) is wrong because scanning identifies known vulnerabilities in image layers at build time but does not enforce runtime syscall restrictions, so it cannot prevent exploitation of a zero-day or unpatched kernel flaw.

104
MCQmedium

A security architect is designing a VPC for a three-tier web application. Which of the following VPC subnet designs provides the most secure isolation for the database tier?

A.Database tier in a private subnet with security group allowing only the application tier
B.Database tier in a separate VPC with VPC peering
C.Database tier in a public subnet with security group allowing only the application tier
D.Database tier in the same subnet as the application tier
AnswerA

Placing the database tier in a private subnet removes any route to the internet, and a security group permitting only the application tier enforces least-privilege, tier-to-tier access. This satisfies the isolation requirement by ensuring no other subnet or external source can reach the database.

Why this answer

Placing the database tier in a private subnet with a security group that only allows traffic from the application tier's security group enforces both network-layer isolation (no route to the internet) and identity-based access control (SG-to-SG referencing). This is the AWS-recommended pattern for three-tier architectures because it minimizes the attack surface and prevents lateral movement from compromised web-tier instances. The database has no public IP and no route to an internet gateway, so it cannot be reached directly from outside the VPC.

Exam trap

CCSP often tests the misconception that VPC peering or public subnets with tight security groups provide equivalent isolation, when subnet-level private placement plus SG chaining is the canonical secure design.

How to eliminate wrong answers

Option B is wrong because a separate VPC with peering adds operational complexity and still requires security groups/NACLs to restrict access — peering alone does not provide more isolation than a properly configured private subnet, and it can widen the blast radius if peering routes are misconfigured. Option C is wrong because a public subnet exposes the database to internet-routable addressing, and a security group alone is a weaker control than subnet-level isolation. Option D is wrong because co-locating the database with the application tier removes network segmentation entirely, allowing any compromised app instance to reach the database directly.

105
MCQhard

A financial services firm runs regulated workloads on Microsoft Azure. Auditors require that disk encryption keys for IaaS virtual machines remain under the firm's exclusive control, that the keys never leave a hardware security module, and that the firm can revoke access to the keys at any time, rendering the disks unreadable. The firm does not want Microsoft to be able to decrypt the disks without an explicit grant. Which Azure disk encryption configuration meets these requirements?

A.Azure Disk Encryption with BitLocker keys wrapped by a customer key held in Azure Key Vault Managed HSM
B.Server-side encryption with customer-managed keys stored in Azure Key Vault, using software-protected keys
C.Azure Storage Service Encryption with infrastructure encryption enabled on the managed disks
D.Azure Disk Encryption with BitLocker keys stored in an Azure Key Vault that uses platform-managed keys
AnswerA

Azure Key Vault Managed HSM provides a single-tenant, FIPS 140-2 Level 3 validated hardware security module where the customer's key material never leaves the HSM boundary. Azure Disk Encryption uses BitLocker for Windows or dm-crypt for Linux and wraps the volume keys with the customer's key-encryption key. Revoking or disabling that key makes the disks unreadable, and Microsoft cannot decrypt without an explicit grant, satisfying every stated requirement.

Why this answer

The auditors require customer-exclusive key custody in a hardware security module plus the ability to revoke access and render disks unreadable. Azure Key Vault Managed HSM supplies single-tenant, hardware-backed key storage, and Azure Disk Encryption wraps the volume keys with a customer key from that HSM. Disabling or revoking the key-encryption key effectively crypto-shreds the disks, which platform-managed or software-protected keys cannot achieve.

Exam trap

The trap here is treating any customer-managed key as equivalent to a hardware security module-backed key, when software-protected keys do not meet a strict HSM custody requirement.

106
Multi-Selectmedium

A cloud security auditor is reviewing container runtime configurations. Which TWO practices help prevent a container from compromising the host operating system?

Select 2 answers
A.Using a read-only root filesystem
B.Disabling SELinux inside the container
C.Running containers in privileged mode
D.Dropping all Linux capabilities
E.Mapping the host's Docker socket into the container
AnswersA, D

A read-only root filesystem prevents processes inside the container from writing to or modifying the underlying host-mounted filesystem, blocking a common container-to-host compromise path. It satisfies the requirement to stop containers compromising the host operating system.

Why this answer

Option A, using a read-only root filesystem, is correct because it prevents a compromised container process from writing malicious files, modifying binaries, or persisting changes to the container's filesystem, which limits the ability to tamper with the host through mounted volumes or writable layers. Option D, dropping all Linux capabilities, is correct because Linux capabilities grant fine-grained kernel privileges (e.g., CAP_SYS_ADMIN, CAP_NET_ADMIN); dropping all of them removes the ability to perform privileged operations like mounting filesystems, loading kernel modules, or manipulating network stacks that could be leveraged to escape the container and affect the host. Option B is wrong because disabling SELinux removes a mandatory access control layer that confines container processes, weakening host protection rather than strengthening it.

Option C is wrong because privileged mode gives the container nearly all host capabilities and device access, dramatically increasing the risk of host compromise. Option E is wrong because mapping the host's Docker socket into a container effectively grants control over the Docker daemon, allowing the container to launch privileged containers or access the host, which is a well-known container escape vector.

107
MCQmedium

A DevOps team deploys workloads on a public cloud using infrastructure as code. A security review finds that a developer's pipeline credentials can both modify production network security groups and read secrets from the key management service. Which cloud infrastructure security principle is most directly violated?

A.Immutable infrastructure with version-controlled deployment artifacts
B.Separation of duties enforced through least-privilege IAM roles
C.Data residency controls restricting where tenant data is stored
D.Defense in depth using layered network and host controls
AnswerB

Separation of duties requires that no single identity hold both the ability to change protective controls and the ability to access the assets those controls protect. A pipeline credential that can alter production security groups and read secrets can silently disable defenses before exfiltrating data, which is exactly the toxic combination this principle is designed to prevent.

Why this answer

The pipeline identity combines the power to weaken production network controls with the power to read protected secrets, so a single compromised credential can both disable defenses and steal data. Enforcing separation of duties through least-privilege IAM roles splits these capabilities across distinct identities, removing the toxic combination the review uncovered.

Exam trap

The trap here is reaching for a broad architectural principle like defense in depth when the finding is specifically about one identity holding conflicting privileges that defeat separation of duties.

108
MCQhard

A financial services company runs a critical workload on AWS. The security team must ensure that all data at rest in Amazon S3 is encrypted with keys that the company controls and that the keys are stored in a hardware security module (HSM) separate from the cloud provider's default HSM. The company also requires the ability to immediately revoke access to the keys. Which solution meets these requirements?

A.Use S3 server-side encryption with AWS KMS custom key store backed by AWS CloudHSM (SSE-KMS with custom key store).
B.Use S3 server-side encryption with Amazon S3 managed keys (SSE-S3).
C.Use S3 server-side encryption with AWS KMS customer managed keys (SSE-KMS).
D.Use S3 client-side encryption with a customer-provided key stored in AWS Secrets Manager.
AnswerA

A KMS custom key store allows you to use AWS CloudHSM clusters that you control, providing a dedicated HSM separate from the default AWS KMS HSMs. You can immediately revoke access by removing the key from the custom key store or deleting the key. This satisfies both the separate HSM and immediate revocation requirements.

Why this answer

The requirement is for customer-controlled keys stored in a dedicated HSM separate from the cloud provider's default HSM, with immediate revocation. AWS KMS custom key store backed by AWS CloudHSM provides exactly this: you control the HSM cluster, and you can revoke access by disassociating the key or deleting it. Other options either use provider-managed HSMs or lack HSM separation.

Exam trap

The trap here is confusing customer managed keys in AWS KMS with customer-controlled HSMs; a custom key store is required to use your own CloudHSM cluster, not just any KMS key.

109
MCQmedium

A cloud security architect is designing a multi-tenant environment using Type 1 hypervisors. Which of the following is the primary security risk associated with this architecture?

A.Insecure VM migration between hosts
B.Insufficient logging of hypervisor events
C.Resource contention leading to denial of service
D.VM escape from guest to hypervisor
AnswerD

A VM escape exploits a hypervisor or virtualisation bug to break out of the guest and execute on the host, compromising every co-resident tenant's VMs. This is the primary risk because the hypervisor is the sole isolation boundary in Type 1 architectures.

Why this answer

In a Type 1 (bare-metal) hypervisor multi-tenant architecture, the hypervisor is the highest-privilege software layer controlling all guest VMs, memory, and virtual devices. A VM escape exploits a hypervisor or virtual-device vulnerability to break out of the guest's isolation boundary and execute code at the hypervisor level, compromising every other tenant on that host. This is the primary and most severe security risk because it defeats the fundamental tenant-isolation guarantee that multi-tenancy depends on.

Exam trap

CCSP often tests the distinction between operational risks (logging, resource contention, migration) and the architectural isolation-breaking risk (VM escape) — candidates pick a plausible-sounding operational issue instead of the fundamental multi-tenancy threat.

How to eliminate wrong answers

Option A is wrong because insecure VM migration (e.g., unencrypted live migration traffic) is a real but secondary risk that can be mitigated with TLS/encryption and is not unique to Type 1 hypervisors. Option B is wrong because insufficient hypervisor event logging is an operational/visibility gap, not the primary architectural security risk of multi-tenancy. Option C is wrong because resource contention causing DoS is an availability concern addressed by resource quotas and QoS, not the core isolation-breaking risk.

110
MCQmedium

A cloud security analyst is reviewing the network architecture of a VPC. The security team wants to block all traffic from a known malicious IP address at the subnet level. Which AWS network security component should they use?

A.Network ACL (NACL)
B.Transit gateway
C.Security group
D.VPC peering connection
AnswerA

Network ACLs are stateless, subnet-level filters that evaluate allow and deny rules against source and destination IP addresses. A deny rule for the malicious IP therefore blocks its traffic before it reaches any instance in the subnet, matching the subnet-level blocking constraint.

Why this answer

NACLs (Network Access Control Lists) are stateless firewalls that operate at the subnet level and support both allow and deny rules. Security groups are stateful and only support allow rules at the instance level.

111
MCQmedium

A cloud security architect is designing a multi-tenant SaaS platform on AWS. The platform must ensure that each tenant's data is logically isolated and that a compromised tenant cannot access another tenant's resources. The architect decides to use separate AWS accounts per tenant and wants to centralize security management. Which AWS service should be used to manage these accounts and apply security policies centrally?

A.AWS IAM Identity Center
B.AWS Organizations
C.AWS Resource Access Manager (RAM)
D.AWS Control Tower
AnswerB

AWS Organizations allows you to centrally manage multiple AWS accounts, apply service control policies (SCPs) to enforce security guardrails, and consolidate billing. It is the correct choice for centralizing security management across many accounts, enabling isolation between tenants while maintaining administrative control.

Why this answer

AWS Organizations is designed to centrally manage multiple AWS accounts, apply service control policies (SCPs) to enforce security boundaries, and simplify billing. It enables logical isolation by placing each tenant in a separate account while allowing centralized security governance. The other services provide access management, governance automation, or resource sharing but do not fulfill the core requirement of central account management and policy enforcement.

Exam trap

The trap here is confusing account access management or governance automation with the foundational service that actually groups and controls multiple accounts.

← PreviousPage 2 of 2 · 111 questions total

Ready to test yourself?

Try a timed practice session using only Cloud Platform and Infrastructure Security questions.