1. Which cloud security risk is mitigated by implementing multi-
factor authentication (MFA)?
A. Data corruption
B. Account hijacking
C. Server downtime
D. Unauthorized data deletion
Answer: b) Account hijacking
Rationale: Multi-factor authentication (MFA) adds an additional
layer of security, requiring users to provide multiple forms of
identification, which significantly reduces the risk of account
hijacking.
2. What type of cloud security control is a firewall considered?
A. Preventative
B. Detective
C. Corrective
D. Compensating
Answer: a) Preventative
Rationale: Firewalls are a preventative security control that blocks
unauthorized access to a network or system, helping to reduce the
risk of cyberattacks.
,3. Which of the following methods is most commonly used to
secure communication between cloud applications and users?
A. Symmetric encryption
B. Public Key Infrastructure (PKI)
C. Data masking
D. Transport Layer Security (TLS)
Answer: d) Transport Layer Security (TLS)
Rationale: TLS is the standard protocol used to secure
communications over the internet by encrypting the data
transmitted between cloud applications and users.
4. What is the role of vulnerability management in cloud security?
A. To ensure that applications are installed and updated regularly
B. To identify, assess, and mitigate vulnerabilities in cloud
environments
C. To manage users and their access rights
D. To monitor the performance of cloud resources
Answer: b) To identify, assess, and mitigate vulnerabilities in
cloud environments
Rationale: Vulnerability management involves identifying
potential weaknesses in cloud resources and applications,
assessing the risk, and implementing mitigation strategies to
reduce exposure.
, 5. Which cloud security control is designed to monitor the use of
cloud services and detect inappropriate behavior?
A. Intrusion Prevention System (IPS)
B. Security Information and Event Management (SIEM)
C. Data Loss Prevention (DLP)
D. Virtual Private Network (VPN)
Answer: b) Security Information and Event Management (SIEM)
Rationale: SIEM systems collect, analyze, and alert administrators
to suspicious activities or security incidents in real time, helping
detect potential misuse of cloud resources.
6. What does data sovereignty refer to in the context of cloud
security?
A. The control over encryption keys for cloud data
B. The legal and regulatory requirements for storing and
processing data
C. The process of securing data during transmission
D. The ability to control data retention and backups
Answer: b) The legal and regulatory requirements for storing and
processing data
Rationale: Data sovereignty refers to the laws and regulations
governing where and how data is stored and processed, especially
factor authentication (MFA)?
A. Data corruption
B. Account hijacking
C. Server downtime
D. Unauthorized data deletion
Answer: b) Account hijacking
Rationale: Multi-factor authentication (MFA) adds an additional
layer of security, requiring users to provide multiple forms of
identification, which significantly reduces the risk of account
hijacking.
2. What type of cloud security control is a firewall considered?
A. Preventative
B. Detective
C. Corrective
D. Compensating
Answer: a) Preventative
Rationale: Firewalls are a preventative security control that blocks
unauthorized access to a network or system, helping to reduce the
risk of cyberattacks.
,3. Which of the following methods is most commonly used to
secure communication between cloud applications and users?
A. Symmetric encryption
B. Public Key Infrastructure (PKI)
C. Data masking
D. Transport Layer Security (TLS)
Answer: d) Transport Layer Security (TLS)
Rationale: TLS is the standard protocol used to secure
communications over the internet by encrypting the data
transmitted between cloud applications and users.
4. What is the role of vulnerability management in cloud security?
A. To ensure that applications are installed and updated regularly
B. To identify, assess, and mitigate vulnerabilities in cloud
environments
C. To manage users and their access rights
D. To monitor the performance of cloud resources
Answer: b) To identify, assess, and mitigate vulnerabilities in
cloud environments
Rationale: Vulnerability management involves identifying
potential weaknesses in cloud resources and applications,
assessing the risk, and implementing mitigation strategies to
reduce exposure.
, 5. Which cloud security control is designed to monitor the use of
cloud services and detect inappropriate behavior?
A. Intrusion Prevention System (IPS)
B. Security Information and Event Management (SIEM)
C. Data Loss Prevention (DLP)
D. Virtual Private Network (VPN)
Answer: b) Security Information and Event Management (SIEM)
Rationale: SIEM systems collect, analyze, and alert administrators
to suspicious activities or security incidents in real time, helping
detect potential misuse of cloud resources.
6. What does data sovereignty refer to in the context of cloud
security?
A. The control over encryption keys for cloud data
B. The legal and regulatory requirements for storing and
processing data
C. The process of securing data during transmission
D. The ability to control data retention and backups
Answer: b) The legal and regulatory requirements for storing and
processing data
Rationale: Data sovereignty refers to the laws and regulations
governing where and how data is stored and processed, especially