MASTER THE C268 EXAM: 125 PRACTICE QUESTIONS &
DETAILED ANSWER EXPLANATIONS (2026 EDITION)
Cloud Security & Cybersecurity / Infrastructure Security
Exam coverage:-
• Section A (Q1–Q25): Cloud concepts, NIST definitions,
deployment and service models, shared responsibility, and
cloud security fundamentals.
• Section B (Q26–Q55): Cloud data life cycle, data security
controls, encryption, key management, and data destruction.
• Section C (Q56–Q85): Cloud platform and infrastructure
security, IAM, network security, hypervisors, containers, and
workload protection.
• Section D (Q86–Q105): Cloud application security, OWASP
Top 10, secure coding, API security, and application testing.
• Section E (Q106–Q125): Cloud security operations, SOC,
SIEM, incident response, compliance, and regulatory
standards.
SECTION A: CLOUD CONCEPTS, ARCHITECTURE & DESIGN
(Q1–Q25)
, Page 2 of 74
1. Which NIST essential characteristic of cloud computing
enables a consumer to unilaterally provision computing
capabilities automatically without requiring human interaction
with each service provider?
A) Resource pooling
B) On-demand self-service
C) Broad network access
D) Rapid elasticity
CORRECT ANSWER: B) On-demand self-service
RATIONALE: Option B is correct because on-demand self-
service allows consumers to provision computing capabilities
automatically without human interaction. Option A is incorrect
because resource pooling refers to multi-tenant sharing. Option
C is incorrect because broad network access refers to
availability over the network. Option D is incorrect because
rapid elasticity refers to scaling capabilities.
2. In the shared responsibility model for IaaS, which security
control is the sole responsibility of the cloud service provider
(CSP)?
A) Guest OS patching
B) Application code security
C) Physical security of the hypervisor host nodes
D) Network ACL configuration
, Page 3 of 74
CORRECT ANSWER: C) Physical security of the hypervisor
host nodes
RATIONALE: Option C is correct because physical security of
the hypervisor host nodes is always the CSP's sole
responsibility under IaaS. Option A is incorrect because guest
OS patching is the customer's responsibility. Option B is
incorrect because application code security is the customer's
responsibility. Option D is incorrect because network ACL
configuration is the customer's responsibility.
3. Which cloud deployment model is provisioned for exclusive
use by a single organization comprising multiple consumers?
A) Public cloud
B) Private cloud
C) Community cloud
D) Hybrid cloud
CORRECT ANSWER: B) Private cloud
RATIONALE: Option B is correct because a private cloud is
provisioned for exclusive use by a single organization. Option A
is incorrect because public cloud is open to the general public.
Option C is incorrect because community cloud is shared by
several organizations. Option D is incorrect because hybrid
cloud combines two or more distinct cloud models.
4. Which cloud service model gives the customer the most
control over the underlying infrastructure?
, Page 4 of 74
A) SaaS
B) PaaS
C) IaaS
D) FaaS
CORRECT ANSWER: C) IaaS
RATIONALE: Option C is correct because IaaS provides the
customer with the most control over the infrastructure,
including operating systems, storage, and deployed
applications. Option A is incorrect because SaaS provides the
least control. Option B is incorrect because PaaS provides
control over deployed applications only. Option D is incorrect
because FaaS abstracts infrastructure management.
5. What is the primary purpose of the Cloud Security Alliance
(CSA) Security Guidance?
A) To provide a certification framework for cloud providers
B) To offer best practices for cloud security across all domains
C) To replace NIST standards
D) To mandate regulatory compliance
CORRECT ANSWER: B) To offer best practices for cloud
security across all domains
RATIONALE: Option B is correct because the CSA Security
Guidance provides best practices for cloud security across all
domains. Option A is incorrect because the CSA provides
guidance, not certification. Option C is incorrect because the