1. Which of the following is a security control that prevents
unauthorized access to cloud applications?
A. Data encryption
B. Identity and Access Management (IAM)
C. Cloud workload monitoring
D. Virtual Machine (VM) isolation
Answer: b) Identity and Access Management (IAM)
Rationale: IAM is essential for managing user identities and
controlling their access to cloud applications, ensuring that only
authorized users can access specific resources.
2. Which type of cloud deployment model combines public and
private clouds to allow data and applications to be shared between
them?
A. Hybrid cloud
B. Community cloud
C. Public cloud
D. Private cloud
Answer: a) Hybrid cloud
,Rationale: A hybrid cloud allows organizations to use both private
and public cloud services, offering flexibility and scalability while
maintaining control over sensitive data.
3. Which of the following is an example of an attack that exploits
vulnerabilities in cloud-based applications or their infrastructure?
A. Phishing
B. Cross-Site Request Forgery (CSRF)
C. Malware injection into cloud databases
D. Data storage encryption failure
Answer: c) Malware injection into cloud databases
Rationale: Malware injections into cloud databases exploit
application vulnerabilities to compromise data and infrastructure,
often leading to significant data breaches.
4. What is the primary function of a Virtual Private Network
(VPN) in a cloud environment?
A. Encrypts data stored on cloud servers
B. Provides a secure connection between a user and the cloud
C. Manages access to cloud resources
D. Monitors cloud usage and activities
Answer: b) Provides a secure connection between a user and the
cloud
, Rationale: A VPN creates a secure, encrypted tunnel for data
transmission between the user's device and the cloud, preventing
unauthorized access and ensuring data confidentiality.
5. Which of the following is an important consideration when
developing a cloud incident response plan?
A. Avoiding the use of encryption tools
B. Ensuring all team members are aware of their roles and
responsibilities
C. Ignoring vendor-specific security guidelines
D. Disabling automatic threat detection tools
Answer: b) Ensuring all team members are aware of their roles and
responsibilities
Rationale: A successful incident response plan requires clear
communication and defined roles for all team members to ensure
an efficient and coordinated response to security incidents in the
cloud.
6. Which cloud security risk is mitigated by implementing multi-
factor authentication (MFA)?
A. Data corruption
B. Account hijacking
C. Server downtime
D. Unauthorized data deletion
unauthorized access to cloud applications?
A. Data encryption
B. Identity and Access Management (IAM)
C. Cloud workload monitoring
D. Virtual Machine (VM) isolation
Answer: b) Identity and Access Management (IAM)
Rationale: IAM is essential for managing user identities and
controlling their access to cloud applications, ensuring that only
authorized users can access specific resources.
2. Which type of cloud deployment model combines public and
private clouds to allow data and applications to be shared between
them?
A. Hybrid cloud
B. Community cloud
C. Public cloud
D. Private cloud
Answer: a) Hybrid cloud
,Rationale: A hybrid cloud allows organizations to use both private
and public cloud services, offering flexibility and scalability while
maintaining control over sensitive data.
3. Which of the following is an example of an attack that exploits
vulnerabilities in cloud-based applications or their infrastructure?
A. Phishing
B. Cross-Site Request Forgery (CSRF)
C. Malware injection into cloud databases
D. Data storage encryption failure
Answer: c) Malware injection into cloud databases
Rationale: Malware injections into cloud databases exploit
application vulnerabilities to compromise data and infrastructure,
often leading to significant data breaches.
4. What is the primary function of a Virtual Private Network
(VPN) in a cloud environment?
A. Encrypts data stored on cloud servers
B. Provides a secure connection between a user and the cloud
C. Manages access to cloud resources
D. Monitors cloud usage and activities
Answer: b) Provides a secure connection between a user and the
cloud
, Rationale: A VPN creates a secure, encrypted tunnel for data
transmission between the user's device and the cloud, preventing
unauthorized access and ensuring data confidentiality.
5. Which of the following is an important consideration when
developing a cloud incident response plan?
A. Avoiding the use of encryption tools
B. Ensuring all team members are aware of their roles and
responsibilities
C. Ignoring vendor-specific security guidelines
D. Disabling automatic threat detection tools
Answer: b) Ensuring all team members are aware of their roles and
responsibilities
Rationale: A successful incident response plan requires clear
communication and defined roles for all team members to ensure
an efficient and coordinated response to security incidents in the
cloud.
6. Which cloud security risk is mitigated by implementing multi-
factor authentication (MFA)?
A. Data corruption
B. Account hijacking
C. Server downtime
D. Unauthorized data deletion