CS – D320 ITCL 3202 Managing Cloud Security
Comprehensive Objective Assessment (Qns &
Ans)
2025
Multiple Choice
A company uses Infrastructure as a Service (IaaS) on AWS.
Which security responsibility rests primarily with the customer?
a) Physical security of data centers
b) Hypervisor patch management
c) Guest operating system configuration
d) Hardware maintenance
ANS: c) Guest operating system configuration
Rationale: In IaaS, the customer manages the OS while the
provider manages the infrastructure.
©2025
,Which of the following best mitigates unauthorized access to
sensitive data in a multi-tenant cloud environment?
a) Network segmentation
b) Data encryption at rest
c) Redundant storage
d) Software-defined networking
ANS: b) Data encryption at rest
Rationale: Encryption at rest helps protect data from unauthorized
access, isolating data between tenants.
A firm deploys a cloud-native application using containers and
orchestrates them with Kubernetes. What is the best practice to
secure inter-pod communications?
a) Use plaintext traffic
b) Assign public IPs to pods
c) Implement network policies and mutual TLS
d) Only use private clusters
ANS: c) Implement network policies and mutual TLS
Rationale: Network policies restrict traffic, while mutual TLS
secures communications.
©2025
, Which of these actions most directly addresses the risk of
excessive permissions in a cloud IAM configuration?
a) Single sign-on
b) Role-based access control (RBAC)
c) Audit logging
d) Data loss prevention
ANS: b) Role-based access control (RBAC)
Rationale: RBAC ensures users are granted minimal, necessary
access aligned with their roles.
What key protocol provides secure authentication and
authorization specifically to federate identities across multiple
cloud services?
a) SSL
b) SAML
c) IMAP
d) SNMP
ANS: b) SAML
Rationale: SAML is widely used for federated identity and access
management in cloud services.
Fill-in-the-Blank
©2025
Comprehensive Objective Assessment (Qns &
Ans)
2025
Multiple Choice
A company uses Infrastructure as a Service (IaaS) on AWS.
Which security responsibility rests primarily with the customer?
a) Physical security of data centers
b) Hypervisor patch management
c) Guest operating system configuration
d) Hardware maintenance
ANS: c) Guest operating system configuration
Rationale: In IaaS, the customer manages the OS while the
provider manages the infrastructure.
©2025
,Which of the following best mitigates unauthorized access to
sensitive data in a multi-tenant cloud environment?
a) Network segmentation
b) Data encryption at rest
c) Redundant storage
d) Software-defined networking
ANS: b) Data encryption at rest
Rationale: Encryption at rest helps protect data from unauthorized
access, isolating data between tenants.
A firm deploys a cloud-native application using containers and
orchestrates them with Kubernetes. What is the best practice to
secure inter-pod communications?
a) Use plaintext traffic
b) Assign public IPs to pods
c) Implement network policies and mutual TLS
d) Only use private clusters
ANS: c) Implement network policies and mutual TLS
Rationale: Network policies restrict traffic, while mutual TLS
secures communications.
©2025
, Which of these actions most directly addresses the risk of
excessive permissions in a cloud IAM configuration?
a) Single sign-on
b) Role-based access control (RBAC)
c) Audit logging
d) Data loss prevention
ANS: b) Role-based access control (RBAC)
Rationale: RBAC ensures users are granted minimal, necessary
access aligned with their roles.
What key protocol provides secure authentication and
authorization specifically to federate identities across multiple
cloud services?
a) SSL
b) SAML
c) IMAP
d) SNMP
ANS: b) SAML
Rationale: SAML is widely used for federated identity and access
management in cloud services.
Fill-in-the-Blank
©2025