wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

035_Cloud-specific Vulnerabilities – CompTIA Security+ –

Total questions: 25

Worksheet time: 13mins

Name
Class
Date
1.

What is a common reason cloud-hosted codebases remain vulnerable?

a)

They are air-gapped from the internet

b)

They only support Linux environments

c)

They run on blockchain platforms

d)

They use zero trust architecture

e)

Unpatched systems with serious vulnerabilities

2.

What percentage of organizations do not use MFA for their cloud consoles?

a)

10%

b)

25%

c)

33%

d)

76%

e)

91%

3.

Why is global accessibility in the public cloud a risk?

a)

It breaks encryption by default

b)

It forces apps to shut down during maintenance

c)

It increases exposure to global threats

d)

It limits access to only internal users

e)

It prevents users from accessing services

4.

What kind of attack can exploit unpatched cloud systems?

a)

Bluejacking attacks

b)

Brute force on local printers

c)

Man-in-the-middle in offline mode

d)

Physical tampering of routers

e)

Remote Code Execution (RCE)

5.

What is a common flaw related to input sanitization in cloud apps?

a)

ARP spoofing

b)

Cross-Site Scripting (XSS)

c)

Fileless malware

d)

Signal jamming

e)

VPN leakage

6.

What kind of injection attack can lead to cloud data theft?

a)

Cookie Poisoning

b)

DNS Tunneling

c)

Drive-by Download

d)

MAC Flooding

e)

SQL Injection

7.

What vulnerability was notable for being easy to exploit and severe?

a)

BlueKeep

b)

Heartbleed

c)

Log4j

d)

PrintNightmare

e)

WannaCry

8.

Why are DoS and DDoS attacks a major concern in the cloud?

a)

Cloud apps are globally accessible

b)

Cloud apps are rarely backed up

c)

Cloud services use firewalls only

d)

They can bypass two-factor authentication

e)

They only target mobile applications

9.

What does Out-of-Bounds Write allow attackers to do?

a)

Access restricted memory

b)

Change Wi-Fi passwords

c)

Disable cloud billing

d)

Modify MAC addresses

e)

Spoof IP addresses

10.

What is one risk of not patching cloud systems?

a)

Cloud service outages

b)

Firewall misconfiguration

c)

IP address leakage

d)

Increased bandwidth costs

e)

Vulnerability to critical CVEs

11.

What can misconfigured authentication lead to?

a)

Easier user onboarding

b)

Faster performance

c)

Improved encryption

d)

Increased replication speed

e)

Unauthorized access

12.

What do MFA and proper credential management help prevent?

a)

Data deduplication

b)

File compression issues

c)

Increased latency

d)

Overclocking errors

e)

Unauthorized access

13.

Why must both OS and cloud applications be patched regularly?

a)

To allow auto-scaling

b)

To improve UI design

c)

To increase color depth

d)

To prevent escalation of compromise

e)

To prevent scheduled downtime

14.

Which attack exploits lack of input validation?

a)

DDoS

b)

Packet sniffing

c)

RFID cloning

d)

SQL Injection

e)

SYN flood

15.

What does a Directory Traversal attack allow?

a)

Access to unauthorized folders

b)

Compression of cloud images

c)

Lossless video streaming

d)

Modification of DNS entries

e)

Shutdown of hypervisors

16.

What makes the public cloud appealing but also risky?

a)

Built-in AI

b)

Global access

c)

Lack of bandwidth

d)

Offline-first mode

e)

Private DNS

17.

What type of vulnerability did Spring Cloud Function have?

a)

IPv6 deprecation

b)

PDF rendering glitch

c)

QR code generation failure

d)

Remote system control

e)

Token refresh errors

18.

What is the CVSS score range indicating a critical vulnerability?

a)

1 or lower

b)

7 or higher

c)

Below 3

d)

Between 4 and 5

e)

Exactly 5.5

19.

What is a primary security concern with misconfigurations?

a)

Increased software licensing

b)

Low storage quota

c)

Overuse of RAM

d)

Slower CPU cycles

e)

System-wide compromise

20.

What risk does lack of MFA primarily increase?

a)

Cloud cost inflation

b)

Email marketing issues

c)

Faster file downloads

d)

Inconsistent UI themes

e)

Unauthorized account access

21.

Why is input validation critical in cloud applications?

a)

To enhance GPU rendering

b)

To improve storage tiering

c)

To minimize CSS overhead

d)

To prevent code injection attacks

e)

To reduce database size

22.

What does memory corruption through Out-of-Bounds Write lead to?

a)

Bluetooth pairing

b)

DNS replication

c)

JPEG compression

d)

System crashes

e)

UI misalignment

23.

What happens when cloud systems are not patched?

a)

They disconnect from VPNs

b)

They lose mobile compatibility

c)

They remain vulnerable to known exploits

d)

They shift to IPv6 automatically

e)

They start using redundant DNS

24.

What kind of data can attackers extract via SQL Injection?

a)

BIOS settings

b)

Cloud-stored data

c)

Encrypted Wi-Fi packets

d)

Ethernet MAC addresses

e)

USB firmware

25.

What is the purpose of enforcing proper credentials and configuration?

a)

To ensure secure authentication

b)

To improve server temperature

c)

To manage hardware upgrades

d)

To simplify UX

e)

To speed up loading times