NEW
Font size
Worksheets035_Cloud-specific Vulnerabilities – CompTIA Security+ –
Total questions: 25
Worksheet time: 13mins
What is a common reason cloud-hosted codebases remain vulnerable?
They are air-gapped from the internet
They only support Linux environments
They run on blockchain platforms
They use zero trust architecture
Unpatched systems with serious vulnerabilities
What percentage of organizations do not use MFA for their cloud consoles?
10%
25%
33%
76%
91%
Why is global accessibility in the public cloud a risk?
It breaks encryption by default
It forces apps to shut down during maintenance
It increases exposure to global threats
It limits access to only internal users
It prevents users from accessing services
What kind of attack can exploit unpatched cloud systems?
Bluejacking attacks
Brute force on local printers
Man-in-the-middle in offline mode
Physical tampering of routers
Remote Code Execution (RCE)
What is a common flaw related to input sanitization in cloud apps?
ARP spoofing
Cross-Site Scripting (XSS)
Fileless malware
Signal jamming
VPN leakage
What kind of injection attack can lead to cloud data theft?
Cookie Poisoning
DNS Tunneling
Drive-by Download
MAC Flooding
SQL Injection
What vulnerability was notable for being easy to exploit and severe?
BlueKeep
Heartbleed
Log4j
PrintNightmare
WannaCry
Why are DoS and DDoS attacks a major concern in the cloud?
Cloud apps are globally accessible
Cloud apps are rarely backed up
Cloud services use firewalls only
They can bypass two-factor authentication
They only target mobile applications
What does Out-of-Bounds Write allow attackers to do?
Access restricted memory
Change Wi-Fi passwords
Disable cloud billing
Modify MAC addresses
Spoof IP addresses
What is one risk of not patching cloud systems?
Cloud service outages
Firewall misconfiguration
IP address leakage
Increased bandwidth costs
Vulnerability to critical CVEs
What can misconfigured authentication lead to?
Easier user onboarding
Faster performance
Improved encryption
Increased replication speed
Unauthorized access
What do MFA and proper credential management help prevent?
Data deduplication
File compression issues
Increased latency
Overclocking errors
Unauthorized access
Why must both OS and cloud applications be patched regularly?
To allow auto-scaling
To improve UI design
To increase color depth
To prevent escalation of compromise
To prevent scheduled downtime
Which attack exploits lack of input validation?
DDoS
Packet sniffing
RFID cloning
SQL Injection
SYN flood
What does a Directory Traversal attack allow?
Access to unauthorized folders
Compression of cloud images
Lossless video streaming
Modification of DNS entries
Shutdown of hypervisors
What makes the public cloud appealing but also risky?
Built-in AI
Global access
Lack of bandwidth
Offline-first mode
Private DNS
What type of vulnerability did Spring Cloud Function have?
IPv6 deprecation
PDF rendering glitch
QR code generation failure
Remote system control
Token refresh errors
What is the CVSS score range indicating a critical vulnerability?
1 or lower
7 or higher
Below 3
Between 4 and 5
Exactly 5.5
What is a primary security concern with misconfigurations?
Increased software licensing
Low storage quota
Overuse of RAM
Slower CPU cycles
System-wide compromise
What risk does lack of MFA primarily increase?
Cloud cost inflation
Email marketing issues
Faster file downloads
Inconsistent UI themes
Unauthorized account access
Why is input validation critical in cloud applications?
To enhance GPU rendering
To improve storage tiering
To minimize CSS overhead
To prevent code injection attacks
To reduce database size
What does memory corruption through Out-of-Bounds Write lead to?
Bluetooth pairing
DNS replication
JPEG compression
System crashes
UI misalignment
What happens when cloud systems are not patched?
They disconnect from VPNs
They lose mobile compatibility
They remain vulnerable to known exploits
They shift to IPv6 automatically
They start using redundant DNS
What kind of data can attackers extract via SQL Injection?
BIOS settings
Cloud-stored data
Encrypted Wi-Fi packets
Ethernet MAC addresses
USB firmware
What is the purpose of enforcing proper credentials and configuration?
To ensure secure authentication
To improve server temperature
To manage hardware upgrades
To simplify UX
To speed up loading times
