Courseiva

Cybersecurity-Apprentice · topic practice

Cloud Security practice questions

Practise Certified Cybersecurity Apprentice (Cybersecurity-Apprentice) Cloud Security practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Reviewed byJohnson Ajibi· MSc IT Security
20 questionsDomain: Cloud Security

What the exam tests

What to know about Cloud Security

Cloud concepts questions usually test the service model (IaaS/PaaS/SaaS) and deployment model (public/private/hybrid/community) appropriate for a given scenario.

IaaS, PaaS and SaaS responsibilities and examples.

Public, private, hybrid and community cloud deployment models.

On-premises vs cloud trade-offs: cost, control, scalability.

How cloud connectivity options (VPN, Direct Connect, ExpressRoute) work.

Watch out for

Common Cloud Security exam traps

  • IaaS gives you infrastructure control; SaaS gives you only the application.
  • Hybrid cloud combines on-premises and public cloud — not two public clouds.
  • Cloud does not automatically mean cheaper or more secure.
  • Management responsibility shifts with each service model (IaaSPaaSSaaS).

Practice set

Cloud Security questions

20 questions · select your answer, then reveal the explanation

An organization runs sensitive workloads inside Microsoft Azure and wants to ensure that Prisma Cloud can inspect compute disks for vulnerabilities without deploying agent software. Which Azure feature does Prisma Cloud leverage to perform agentless disk inspection securely?

A security administrator wants to ensure that Prisma Cloud alerts are actionable and prioritized effectively. Which THREE strategies should the administrator implement within Prisma Cloud? (Choose three)

Question 3mediummultiple choice
Read the full Cloud Security explanation →

An administrator needs to restrict access to the Prisma Cloud administrative console based on corporate IP ranges. Where within the Prisma Cloud platform should the administrator configure trusted IP address restrictions?

A security analyst is reviewing compliance posture using Prisma Cloud Compute and needs to secure cloud workloads. According to the shared responsibility model for a containerized application running on AWS Elastic Kubernetes Service (EKS), who is responsible for patching the container OS base image?

Question 5mediummultiple choice
Read the full Cloud Security explanation →

A security architect is configuring CloudTrail integration for Prisma Cloud across multiple AWS accounts managed through AWS Organizations. Which account deployment method should be used to ensure centralized log ingestion and security posture visibility?

Question 6mediummultiple choice
Read the full Cloud Security explanation →

An auditor requests evidence that public AWS S3 buckets are automatically remediated when discovered by Prisma Cloud. Which feature should the security engineer configure to achieve automated remediation?

A junior cloud engineer is configuring a new AWS S3 bucket and wants to ensure that Prisma Cloud successfully detects public exposure risks. Which Prisma Cloud feature continuously evaluates cloud resource configurations against security benchmarks like CIS?

Question 8mediummultiple choice
Read the full Cloud Security explanation →

A security engineer is writing a custom RQL (Resource Query Language) search in Prisma Cloud to find all AWS EC2 instances that do not have encryption enabled on their root volumes. Which RQL query syntax is correct?

Question 9mediummultiple choice
Read the full Cloud Security explanation →

An enterprise security team deploys Prisma Cloud Compute across their Kubernetes clusters to enforce security policies. A developer attempts to deploy a privileged pod that violates runtime security policies. Which Prisma Cloud component intercepts and blocks this deployment at the admission controller level?

Question 10easymultiple choice
Read the full Cloud Security explanation →

An administrator is deploying Prisma Cloud to secure a multi-cloud environment consisting of AWS and Azure. The administrator needs to understand the boundaries of security management under the shared responsibility model. Which responsibility always remains with the customer regardless of the cloud service model used?

Question 11hardmultiple choice
Read the full Cloud Security explanation →

A DevOps engineer observes that Prisma Cloud Compute vulnerability scans are reporting high severity Common Vulnerabilities and Exposures (CVEs) on running containers, but the build pipeline failed to catch them. How should the engineer integrate Prisma Cloud into the CI/CD pipeline to prevent vulnerable images from being built and pushed?

Question 12easymultiple choice
Read the full Cloud Security explanation →

A security administrator is evaluating cloud environments and needs to determine where customer responsibility ends in an Infrastructure as Service (IaaS) model. Which component is managed entirely by the cloud provider in IaaS?

Question 13hardmultiple choice
Read the full Cloud Security explanation →

An administrator needs to onboard a new Google Cloud Platform (GCP) organization into Prisma Cloud with least-privilege permissions. Which GCP authentication method does Prisma Cloud recommend and support for secure API integration?

Question 14hardmultiple choice
Read the full Cloud Security explanation →

An enterprise has strict compliance requirements requiring visibility into network traffic flows between Kubernetes pods across different namespaces. Which Prisma Cloud Compute feature should be enabled to monitor and enforce layer 7 network segmentation rules inside the cluster?

Question 15mediummultiple choice
Read the full Cloud Security explanation →

An enterprise security team wants to prevent developers from deploying Infrastructure as Code (IaC) templates that contain misconfigurations, such as open security groups. Which Prisma Cloud module should be integrated into the developer workflow (e.g., GitHub or Terraform Cloud)?

Question 16easymultiple choice
Read the full Cloud Security explanation →

A compliance officer needs to verify whether cloud storage buckets across AWS and Azure meet corporate encryption standards. Which Prisma Cloud module provides out-of-the-box compliance reporting against standards such as HIPAA and PCI-DSS?

Question 17mediummultiple choice
Read the full Cloud Security explanation →

An administrator is reviewing Prisma Cloud agentless scanning capabilities for AWS EC2 instances. What is the primary advantage of utilizing agentless scanning compared to deploying the traditional Defender agent on every workload?

Question 18mediummultiple choice
Read the full Cloud Security explanation →

A security analyst receives a Prisma Cloud alert regarding suspicious API activity in an AWS account, indicating potential credential compromise. Which Prisma Cloud module generated this alert by analyzing cloud provider audit logs for anomalous behavior?

Question 19hardmultiple choice
Read the full Cloud Security explanation →

An application security engineer configures Prisma Cloud WAAS (Web Application and API Security) to protect a containerized microservices application running behind an ingress controller. Which deployment method is supported for WAAS in a Kubernetes environment?

Question 20hardmultiple choice
Read the full Cloud Security explanation →

An auditor notices that a cloud account onboarded to Prisma Cloud has generated numerous alerts for unused IAM access keys. Which underlying Prisma Cloud data source is evaluated to detect this condition?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Cloud Security sessions

Start a Cloud Security only practice session

Every question in these sessions is drawn from the Cloud Security domain — nothing else.

Related practice questions

Related Cybersecurity-Apprentice topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the Cybersecurity-Apprentice exam test about Cloud Security?
Cloud concepts questions usually test the service model (IaaS/PaaS/SaaS) and deployment model (public/private/hybrid/community) appropriate for a given scenario.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Cloud Security questions in a focused session?
Yes — the session launcher on this page draws every question from the Cloud Security domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other Cybersecurity-Apprentice topics?
Use the topic links above to move to related areas, or go back to the Cybersecurity-Apprentice question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the Cybersecurity-Apprentice exam covers. They are not copied from any real exam or dump site.