Official Exam 2026/2027 Actual Exam Complete
Questions and Answers Detailed Rationales Pass
Guaranteed - A+ Graded
TABLE OF CONTENTS
Section 1 | Cloud Security Fundamentals and Shared Responsibility | Q1 – Q16
Section 2 | Identity and Access Management in the Cloud | Q17 – Q32
Section 3 | Data Protection and Encryption | Q33 – Q48
Section 4 | Compliance, Legal, and Regulatory Requirements | Q49 – Q64
Section 5 | Incident Response and Cloud Security Operations | Q65 – Q80
Instructions: Choose the single best answer. Pass: 80% in 120 minutes.
══════════════════════════════════════
SECTION 1: CLOUD SECURITY FUNDAMENTALS AND SHARED RESPONSIBILITY Q1 –
Q16
══════════════════════════════════════
Question 1 of 80
A mid-sized healthcare organization is migrating its electronic health record system to
AWS. The CISO is reviewing the AWS shared responsibility model to allocate security
tasks between internal teams and the cloud provider. Under this model, AWS is
responsible for:
A. Configuring the organization's firewall rules and security groups
B. Encrypting patient data stored in the organization's S3 buckets
C. Protecting the global infrastructure that runs all services, including hardware and
facilities ✓ CORRECT
D. Patching the operating system on the organization's EC2 instances
Correct Answer: C
,Rationale: AWS manages the security of the cloud, which includes the underlying global
infrastructure, hardware, software, networking, and facilities that run AWS services.
Choice A describes customer responsibilities within the security in the cloud layer.
Understanding this division prevents dangerous assumptions that the provider handles
all security tasks.
Question 2 of 80
A financial services firm is evaluating cloud deployment models for a new trading
application that handles sensitive transaction data. The firm's compliance team requires
complete control over physical infrastructure while still gaining cloud-like elasticity. The
deployment model that best meets these requirements is:
A. Public cloud with dedicated hosts
B. Private cloud ✓ CORRECT
C. Community cloud shared with other financial institutions
D. Hybrid cloud with public-facing web servers
Correct Answer: B
Rationale: A private cloud provides dedicated infrastructure with complete control over
physical and logical security while offering the scalability and automation benefits of
cloud computing. Choice A still operates on shared physical infrastructure managed by
the provider, which may not satisfy strict compliance requirements for physical control.
Question 3 of 80
A DevOps engineer at a SaaS startup accidentally exposes an Amazon S3 bucket
containing customer profile pictures to the public internet. The breach occurs because
the bucket policy allows s3:GetObject from a Principal of *. This incident most clearly
demonstrates a failure in:
A. AWS infrastructure security
,B. The customer's side of the shared responsibility model ✓ CORRECT
C. AWS network perimeter controls
D. AWS key management service availability
Correct Answer: B
Rationale: Misconfigured bucket policies are customer-side errors within the shared
responsibility model, as AWS provides the tools but the customer must correctly
implement access controls. Choice A incorrectly blames the provider for a configuration
mistake made by the customer. Regular access reviews and automated policy scanning
can prevent such exposures.
Question 4 of 80
A retail company is deploying a new e-commerce platform in Microsoft Azure. The
security architect wants to understand which threats Azure mitigates automatically
versus which require customer action. Azure automatically protects against:
A. SQL injection attacks in the customer's application code
B. DDoS attacks at the network infrastructure layer ✓ CORRECT
C. Cross-site scripting vulnerabilities in custom web pages
D. Weak authentication mechanisms in the customer's API layer
Correct Answer: B
Rationale: Azure provides built-in DDoS protection for its network infrastructure, but
application-layer vulnerabilities such as SQL injection and XSS remain the customer's
responsibility to remediate through secure coding. Choice A describes an application
security issue that platform-level DDoS protection cannot address. Defense in depth
requires both provider and customer controls.
Question 5 of 80
, A government contractor is required to process classified data in a cloud environment.
Under federal cloud security guidelines, the cloud service model that places the greatest
security responsibility on the customer is:
A. Software as a Service
B. Platform as a Service
C. Infrastructure as a Service ✓ CORRECT
D. Function as a Service
Correct Answer: C
Rationale: IaaS places the most security responsibility on the customer, who must
manage everything from the operating system upward, including patching,
configuration, and application security. Choice A shifts nearly all responsibility to the
provider, which may not be acceptable for classified workloads requiring customer
control.
Question 6 of 80
A security analyst is mapping the threat landscape for a cloud-native application. She
identifies that an attacker could exploit a vulnerability in the underlying hypervisor to
escape to other tenants' virtual machines. This threat is primarily mitigated by:
A. The customer's intrusion detection system
B. The cloud provider's infrastructure isolation and hypervisor hardening ✓ CORRECT
C. The customer's web application firewall
D. The customer's data loss prevention policy
Correct Answer: B
Rationale: Hypervisor security and tenant isolation are core provider responsibilities
within the shared responsibility model, as customers have no visibility into or control
over the underlying virtualization layer. Choice A monitors customer workloads but
cannot detect or prevent hypervisor-level attacks. Regular provider audits and
certifications validate these controls.