wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Module 2 - Identity & Access Management

Total questions: 7

Worksheet time: 4mins

Name
Class
Date
1.

A multinational company adopts Google Cloud for its enterprise workloads. The cloud security engineer configures IAM roles to follow the principle of least privilege. The team needs to identify how IAM members are authenticated across different identity types. Which identities do Google Cloud IAM members use to access resources?

a)

For Google Account, Google group, and service account → domain name; for G Suite and Cloud Identity domain → email address

b)

For Google Account, Google group, and service account → email address; for G Suite and Cloud Identity domain → domain name

c)

For Google Account, Google group, and G Suite → domain name; for service account and Cloud Identity domain → email address

d)

For Google Account, Google group, and G Suite → email address; for service account and Cloud Identity domain → domain name

2.

A developer launches an application on an AWS EC2 instance that needs to retrieve images from an S3 bucket. The admin creates a service role with a trust policy that allows the instance to assume the role and a permission policy granting read-only access to the S3 bucket. The application uses the temporary credentials provided by the role. In this scenario, must the developer manage credentials or request additional permissions from the admin?

a)
Yes, the developer must manage credentials manually.
b)
Yes, the developer needs to request additional permissions for S3 access.
c)
No, the developer can use hardcoded credentials instead.
d)
No, the developer does not need to manage credentials or request additional permissions.
3.

A senior cloud engineer, Ava, advises her company's leadership to migrate all applications to a public cloud. After the migration, Ava's team must be able to configure, monitor, and maintain the new cloud platform and applications. Which component of a cloud platform provides these tools and interfaces?

a)

Physical and Environmental Component

b)

Compute Component

c)

Management Component

d)

Virtualization Component

4.

A cloud administrator must create separate subscriptions for each division in Azure but ensure consistent IAM role assignments across all. He needs an automated, repeatable method for provisioning identity and access resources at scale. Which service should he use?

a)

A. Azure AD Privileged Identity Management

b)

B. Azure AD Multi-Factor Authentication

c)

C. Azure AD Identity Protection

d)

D. Azure AD Self-Service Password Reset

5.

Aria is an IT manager at a company that wants to define infrastructure resources like IAM policies, EC2 instances, and networking in reusable templates to reduce human error and enforce consistent access control. Which AWS service should Aria use?

a)

AWS CloudFormation

b)

AWS Config

c)

AWS Inspector

d)

AWS Control Tower

6.

A global enterprise wants to automate provisioning of complex resource stacks including VPCs, IAM roles, and multi-tier applications. They require version-controlled, template-driven infrastructure that scales across regions. Which service meets this need?

a)

AWS OpsWorks

b)

AWS CloudFormation

c)

AWS Config

d)

AWS Organizations

7.

A DevOps team at a large company wants to automatically deploy IAM policies and resource stacks across multiple AWS accounts with minimal manual intervention. They also want rollback capability if a deployment fails. Which service should they use?

a)

AWS Config

b)

AWS Control Tower

c)

AWS CloudFormation

d)

AWS IAM