200 Questions Exam Study Guide
(2026/2027)Graded A+/Instant PDF
Download
Which cloud service model provides customers with virtual machines, storage, and
networking resources while the cloud provider manages the underlying physical
infrastructure?
A. Software as a Service (SaaS)
B. Platform as a Service (PaaS)
C. Infrastructure as a Service (IaaS)
D. Function as a Service (FaaS)
Answer: C. Infrastructure as a Service (IaaS)
IaaS provides virtualized computing resources such as servers, storage, and
networking. The provider manages the physical infrastructure, while the customer
manages the operating systems, applications, and much of the configuration.
Under the cloud shared-responsibility model, which responsibility generally
remains with the customer regardless of whether a public cloud provider is used?
A. Physical data-center security
B. Hypervisor maintenance
C. Protection and appropriate use of customer data
D. Physical server replacement
Answer: C. Protection and appropriate use of customer data
Cloud providers secure the infrastructure they operate, but customers remain
responsible for appropriately protecting their data and configuring services
securely.
,Which security principle requires users to receive only the permissions necessary
to perform their assigned tasks?
A. Defense in depth
B. Separation of duties
C. Least privilege
D. Nonrepudiation
Answer: C. Least privilege
Least privilege limits access to the minimum permissions required. This reduces
the potential impact of compromised accounts or accidental misuse.
A company requires administrators to authenticate with a password and a hardware
security token. Which security control is being implemented?
A. Single sign-on
B. Federation
C. Multifactor authentication
D. Role-based access control
Answer: C. Multifactor authentication
MFA requires two or more authentication factors, such as something the user
knows and something the user possesses.
Which authentication factor is represented by a fingerprint?
A. Something you know
B. Something you have
C. Something you are
D. Somewhere you are
Answer: C. Something you are
Biometric characteristics such as fingerprints, facial characteristics, and iris
patterns are inherence factors, commonly described as “something you are.”
What is the primary purpose of encryption at rest?
,A. Preventing unauthorized network connections
B. Protecting stored data from unauthorized disclosure
C. Increasing application availability
D. Detecting malicious network traffic
Answer: B. Protecting stored data from unauthorized disclosure
Encryption at rest protects information stored on disks, databases, object storage,
and other persistent media.
Which technology protects data while it travels between a user's browser and a
cloud service?
A. Hashing
B. Data masking
C. TLS encryption
D. Disk encryption
Answer: C. TLS encryption
Transport Layer Security (TLS) provides encryption and authentication for data
transmitted across networks.
Which characteristic of a cryptographic hash makes it useful for verifying file
integrity?
A. It can be decrypted with a private key
B. It produces different output every time
C. A small change in the input produces a substantially different digest
D. It compresses files without information loss
Answer: C. A small change in the input produces a substantially different digest
Cryptographic hashes generate fixed-length digests. Even a minor modification to
the original data normally results in a different digest.
Which cloud security control is most directly associated with recording who
accessed a resource and what action they performed?
A. Encryption
B. Tokenization
, C. Audit logging
D. Data classification
Answer: C. Audit logging
Audit logs record security-relevant activities and can support investigations,
compliance, monitoring, and accountability.
A cloud administrator assigns permissions according to predefined job functions
such as database administrator, security analyst, and auditor. Which access-control
model is this?
A. Discretionary access control
B. Mandatory access control
C. Role-based access control
D. Rule-based encryption
Answer: C. Role-based access control
RBAC assigns permissions to roles rather than individually assigning every
permission to every user.
Which security concept assumes that no user, device, or network location should
automatically be trusted?
A. Perimeter security
B. Zero trust
C. Open access
D. Network address translation
Answer: B. Zero trust
Zero trust requires continuous verification and uses principles such as least
privilege, strong authentication, and contextual access decisions.
Which cloud architecture component is commonly used to isolate resources within
a virtual network?
A. Hypervisor
B. Virtual private cloud or virtual network