1. Which of the following is the primary responsibility of a cloud
service provider (CSP) in a shared responsibility model?
A. Data encryption
B. Network security
C. Customer access management
D. Application security
Answer: b) Network security
Rationale: In the shared responsibility model, the cloud service
provider (CSP) is responsible for the security of the cloud
infrastructure, including network security. The customer is
responsible for securing their applications and data within the
cloud environment.
2. What type of encryption protects cloud data when it is being
transmitted between cloud services and users?
A. Symmetric encryption
B. End-to-end encryption
C. Asymmetric encryption
D. Transport Layer Security (TLS)
Answer: d) Transport Layer Security (TLS)
,Rationale: TLS is used to secure data during transmission between
cloud services and users, ensuring confidentiality and integrity of
data in transit.
3. Which type of cloud deployment model combines public and
private clouds to allow data and applications to be shared between
them?
A. Hybrid cloud
B. Community cloud
C. Public cloud
D. Private cloud
Answer: a) Hybrid cloud
Rationale: A hybrid cloud allows organizations to use both private
and public cloud services, offering flexibility and scalability while
maintaining control over sensitive data.
4. Which of the following is a common security vulnerability in
cloud environments that can result from misconfigurations?
A. Data encryption failures
B. Denial of Service (DoS) attacks
C. Insecure API access
D. Data backups
Answer: c) Insecure API access
, Rationale: Misconfigured APIs can expose sensitive data and
systems to attackers. Secure API management and authentication
are critical to preventing these vulnerabilities.
5. What is the role of vulnerability management in cloud security?
A. To ensure that applications are installed and updated regularly
B. To identify, assess, and mitigate vulnerabilities in cloud
environments
C. To manage users and their access rights
D. To monitor the performance of cloud resources
Answer: b) To identify, assess, and mitigate vulnerabilities in
cloud environments
Rationale: Vulnerability management involves identifying
potential weaknesses in cloud resources and applications,
assessing the risk, and implementing mitigation strategies to
reduce exposure.
6. Which of the following best describes the concept of "data
leakage" in a cloud environment?
A. Unintended exposure of sensitive data to unauthorized parties
B. Unauthorized deletion of data from cloud storage
C. Inability to retrieve data after a security breach
D. Slow data transfer rates during cloud migration
service provider (CSP) in a shared responsibility model?
A. Data encryption
B. Network security
C. Customer access management
D. Application security
Answer: b) Network security
Rationale: In the shared responsibility model, the cloud service
provider (CSP) is responsible for the security of the cloud
infrastructure, including network security. The customer is
responsible for securing their applications and data within the
cloud environment.
2. What type of encryption protects cloud data when it is being
transmitted between cloud services and users?
A. Symmetric encryption
B. End-to-end encryption
C. Asymmetric encryption
D. Transport Layer Security (TLS)
Answer: d) Transport Layer Security (TLS)
,Rationale: TLS is used to secure data during transmission between
cloud services and users, ensuring confidentiality and integrity of
data in transit.
3. Which type of cloud deployment model combines public and
private clouds to allow data and applications to be shared between
them?
A. Hybrid cloud
B. Community cloud
C. Public cloud
D. Private cloud
Answer: a) Hybrid cloud
Rationale: A hybrid cloud allows organizations to use both private
and public cloud services, offering flexibility and scalability while
maintaining control over sensitive data.
4. Which of the following is a common security vulnerability in
cloud environments that can result from misconfigurations?
A. Data encryption failures
B. Denial of Service (DoS) attacks
C. Insecure API access
D. Data backups
Answer: c) Insecure API access
, Rationale: Misconfigured APIs can expose sensitive data and
systems to attackers. Secure API management and authentication
are critical to preventing these vulnerabilities.
5. What is the role of vulnerability management in cloud security?
A. To ensure that applications are installed and updated regularly
B. To identify, assess, and mitigate vulnerabilities in cloud
environments
C. To manage users and their access rights
D. To monitor the performance of cloud resources
Answer: b) To identify, assess, and mitigate vulnerabilities in
cloud environments
Rationale: Vulnerability management involves identifying
potential weaknesses in cloud resources and applications,
assessing the risk, and implementing mitigation strategies to
reduce exposure.
6. Which of the following best describes the concept of "data
leakage" in a cloud environment?
A. Unintended exposure of sensitive data to unauthorized parties
B. Unauthorized deletion of data from cloud storage
C. Inability to retrieve data after a security breach
D. Slow data transfer rates during cloud migration