NEW
Font size
WorksheetsMODULE 4-8
Total questions: 56
Worksheet time: 28mins
A government agency uses AWS Snowball to transfer petabytes of classified data from its on-premises datacenter to AWS. The security team requires assurance that the device protects data during transit and at rest. Which mechanism ensures this protection?
Data is transferred unencrypted, but access is restricted to AWS engineers
Data is encrypted using 256-bit encryption, with encryption keys managed by AWS KMS
Data is secured using application-level passwords configured by the customer
Data is stored in plaintext but transported over a secure TLS channel
Abigail, a security analyst at a large organization, configures Google Cloud Security Command Center (SCC) to identify real-time suspicious activities like brute-force login attempts and cryptocurrency mining. Which SCC feature provides this detection capability?
Event Threat Detection
Security Health Analytics
Asset Inventory
Web Security Scanner
Anika is responsible for monitoring her company's cloud environment for security threats. She needs a feature that analyzes logs and events to detect active threats, including brute-force and malware activity. Which SCC feature should Anika use?
Security Health Analytics
Event Threat Detection
Container Threat Detection
IAM Policy Analyzer
James is a GCP customer who wants to continuously monitor his projects for misconfigured firewalls, exposed Cloud Storage buckets, and insecure IAM roles. Which SCC feature should he enable?
Event Threat Detection
Container Threat Detection
Security Health Analytics
Data Loss Prevention API
A media company wants to provide customers with temporary download links to large video files stored in Google Cloud Storage. Links should expire after 24 hours to prevent unauthorized access. Which GCP feature enables this?
Pre-signed IAM Roles
Signed URLs
Cloud CDN Cache Keys
Security Health Analytics
A university research team needs to share large data sets with external collaborators for a limited time, without creating accounts for each user. Which GCP feature allows this?
Signed URLs
IAM Policy Analyzer
Event Threat Detection
Cloud Functions
An e-commerce company generates one-time, expiring links for customer invoices stored in Cloud Storage. Links must expire within 1 hour. Which mechanism supports this?
Cloud CDN
Signed URLs
Signed Policy Documents
IAM Roles with TTL
A legal firm must allow auditors to temporarily download case files from Google Cloud Storage. Access should be granted only for 12 hours and revoked automatically afterward. Which feature should they use?
GCP Signed URLs
Cloud Identity Federation
Security Health Analytics
Cloud VPN
A critical vulnerability is discovered in a web application framework used by multiple VMs in the cloud. The cloud operations team needs to quickly mitigate risk while a permanent patch is being tested. What is the most effective immediate action?
Apply a hotfix to temporarily remediate the vulnerability
Shut down all VMs until the permanent patch is ready
Wait for the vendor to release an official patch
Remove the application from production permanently
Abigail, a security analyst at a growing tech company, wants to enable continuous monitoring for malicious IP activity, unauthorized API calls, and reconnaissance attempts in their AWS environment. Which service should she use?
AWS Shield Standard
AWS CloudTrail
AWS GuardDuty
AWS Inspector
A DevOps team at a fintech startup uses Terraform templates to provision cloud resources. The security team wants to prevent misconfigurations like public S3 buckets or overly permissive IAM policies from being deployed. Which approach should be taken?
Implement policy-as-code tools like Terraform Sentinel or Open Policy Agent to enforce security policies.
Increase manual code reviews for all Terraform templates before deployment.
Rely on cloud provider default security settings to prevent misconfigurations.
Disable all public access to cloud resources regardless of use case.
Ethan is responsible for managing his company's cloud infrastructure using Infrastructure as Code (IaC). He wants to ensure that there are no misconfigurations before provisioning any resources. Which is the best approach Ethan should take to detect misconfigurations in IaC before provisioning?
Manually review all IaC templates before deployment
Use automated IaC scanning tools to detect misconfigurations before provisioning
Rely only on runtime security monitoring after deployment
Disable IaC automation entirely and use manual provisioning
Mason is responsible for the security of his company's cloud infrastructure. He needs an automated service to scan EC2 instances and container workloads for vulnerabilities, exposed network paths, and compliance issues. Which AWS service should Mason use?
AWS GuardDuty
AWS Inspector
AWS Security Hub
AWS Config
The security team at a large e-commerce company wants to receive real-time alerts when GuardDuty detects IAM anomalies or S3 bucket misconfigurations. What does GuardDuty provide in this scenario?
GuardDuty generates security findings in near real time
GuardDuty automatically remediates misconfigurations
GuardDuty blocks suspicious API calls automatically
GuardDuty enforces compliance rules at provisioning
A financial services company requires automatic DNS failover to a disaster recovery site if the main application endpoint becomes unavailable. Which solution should be implemented?
Route 53 Failover with Health Checks
CloudFront Distribution
AWS Shield Advanced
AWS WAF
Benjamin, an auditor, needs a report of all API calls and user actions performed in AWS over the last 90 days for a compliance review. Which service provides this information?
AWS Config
AWS CloudTrail
AWS Security Hub
Amazon Macie
An e-commerce company wants to protect its web application from HTTP floods and other Layer 7 DDoS attacks. Which AWS service provides this protection?
AWS GuardDuty
AWS WAF with Shield Advanced
AWS Shield Standard
AWS Inspector
Avery, a compliance officer at a financial company, needs to track whether S3 buckets are publicly accessible and maintain a history of configuration changes across AWS resources. Which service should they use?
AWS Security Hub
AWS Config
AWS CloudTrail
Amazon Macie
A global e-commerce site wants to ensure that if its primary web server fails, traffic is automatically routed to a backup server in another AWS region. Which Route 53 feature enables this?
Weighted Routing
Latency-Based Routing
DNS Failover with Health Checks
Multivalue Answer Routing
Luna manages a telemedicine platform that must remain accessible to patients at all times. To ensure high availability, she needs to reroute traffic to a backup API gateway if the primary one becomes unavailable. Which Route 53 feature should Luna use?
Failover Routing with Health Checks
Weighted Routing
Latency-Based Routing
Resolver Rules
Grace is developing a cloud application that needs to securely store encryption keys, secrets, and certificates with strong access controls. Which Azure service should she use?
Azure Information Protection
Azure Sentinel
Azure Key Vault
Azure App Service
James, an auditor, requests a 90-day history of S3 bucket configurations to verify compliance with encryption policies. Which AWS service should be used?
AWS CloudTrail
AWS Security Hub
Amazon Macie
AWS Config
A retail company wants to verify which IAM roles had overly permissive policies last month. Which AWS service provides this history?
AWS Security Hub
AWS Config
AWS CloudTrail
Amazon Detective
A manufacturing company needs continuous monitoring of EC2 instance configurations and a historical record of compliance changes for reporting. Which service should be used?
AWS Inspector
AWS GuardDuty
AWS Config
AWS CloudWatch
A financial institution wants to continuously evaluate its EC2 instances and container workloads for vulnerabilities, unintended network exposure, and deviations from best practices. Which AWS service should they enable?
AWS GuardDuty
AWS Inspector
AWS Security Hub
AWS Config
A healthcare company wants real-time detection of IAM role misuse, suspicious API calls, and S3 bucket misconfigurations in AWS. Which service provides these alerts?
AWS CloudTrail
AWS Inspector
AWS GuardDuty
AWS Security Hub
Emma, an IT auditor, is reviewing her company's AWS environment and needs a log of all platform-level API calls and user activity in AWS for the past 90 days. Which AWS service should she use?
AWS Config
AWS Security Hub
AWS CloudTrail
AWS Trusted Advisor
A SaaS provider wants to ensure minimal downtime by automatically redirecting clients to an alternative server if the main one is unreachable. Which AWS service configuration is needed?
AWS CloudTrail
AWS Config
Route 53 Failover with Health Checks
Amazon Macie
An e-commerce platform wants to protect its website from DDoS attacks at layers 3, 4, and 7. Which AWS service provides baseline, always-on protection at no additional cost?
AWS WAF
AWS Shield Standard
AWS GuardDuty
AWS Firewall Manager
A healthcare company wants to centrally manage encryption keys and digital certificates for its cloud-hosted applications. Which Azure service should they implement?
Azure Key Vault
Azure Monitor
Azure DevOps
Azure Logic Apps
Kai is working on a development project and wants to eliminate hardcoded database passwords in the application code by retrieving them securely at runtime. Which Azure service should Kai use?
Azure Key Vault
Azure Blob Storage
Azure AD Conditional Access
Azure Firewall
Jackson is working for a global bank that requires FIPS 140-2 compliance for managing sensitive cryptographic keys in Azure. Which service should Jackson use to meet this requirement?
Azure Key Vault
Azure AD Privileged Identity Management
Azure Storage Accounts
Azure Policy
Maya is working at a SaaS company that must log every request to retrieve keys for audit purposes. Which service provides this auditing capability?
Azure Policy
Azure Key Vault
Azure Sentinel
Azure Monitor
Avery is leading a development team at a software company that needs to enforce centralized management of API tokens, SSH keys, and secrets for all developers. Which Azure service is required?
Azure Security Center
Azure App Service
Azure Key Vault
Azure AD Identity Protection
Mia, a compliance officer at a financial company, wants to review whether S3 buckets were encrypted last month and see historical resource states. Which AWS service should be used?
AWS Config
AWS CloudTrail
AWS Security Hub
Amazon Macie
Harper, working at a financial firm, needs to provide auditors with a complete record of IAM role changes for the last 90 days. Which service offers this?
AWS Config
AWS GuardDuty
AWS Inspector
AWS Trusted Advisor
A retail company wants automated evaluation of compliance with rules such as “EC2 instances must not use public IPs.” Which AWS service should they use?
AWS CloudTrail
AWS Config
AWS Security Hub
Amazon Detective
Abigail, an auditor, needs to determine which EC2 instances had security group changes last quarter. Which AWS service provides this?
AWS Security Hub
AWS Config
AWS CloudTrail
AWS Inspector
A media company requires automatic redirection to a backup server if the primary website fails. Which Route 53 feature enables this?
Weighted Routing
Failover Routing with Health Checks
Latency-Based Routing
Resolver Rules
A financial services company must ensure that if its main website becomes unavailable, customer traffic is automatically redirected to its disaster recovery site to maintain service availability. Which AWS service should be used?
Route 53 Failover with Health Checks
AWS CloudFront
AWS Shield Advanced
AWS WAF
A healthcare provider wants to guarantee API gateway high availability by redirecting clients to a healthy secondary endpoint if the primary fails. Which feature is needed?
Route 53 Failover with Health Checks
Weighted Routing
Latency-Based Routing
Multivalue Answer Routing
Which GCP feature allows external users temporary access without requiring Google identities?
Signed URLs
Event Threat Detection
Cloud Functions
IAM Roles with TTL
A SaaS company wants to minimize downtime by using DNS to automatically redirect traffic to secondary servers if the primary site is unavailable. Which service supports this?
AWS Config
Route 53 Failover with Health Checks
AWS CloudTrail
AWS Macie
A company wants to separate its Google Cloud workloads into tiers (web, app, database). Only the web tier should accept internet traffic, while app and database tiers must only allow internal communications. Which Google Cloud feature enables this network segmentation?
VPC Firewall Rules
Cloud CDN
Cloud Load Balancing
Cloud Storage
Olivia is designing a multi-tier application on GCP and wants to ensure granular control of traffic between the web, app, and database tiers. She needs to restrict traffic so that, for example, only the web tier can communicate with the app tier, and only the app tier can access the database tier. Which GCP feature should Olivia use to achieve this?
VPC Subnets
VPC Firewall Rules
Shared VPC
Cloud Armor
A security operations team at a large financial company uses Microsoft Defender for Cloud to monitor its Azure environment. One morning, Hannah, a security analyst, notices multiple alerts categorized as High severity for suspicious activities. What does a High severity alert indicate?
A. A minor misconfiguration with little risk
B. A confirmed threat or vulnerability requiring immediate action
C. A warning about resource costs exceeding budget
D. An advisory about Azure service availability
A financial services firm wants to ensure private, secure, low-latency connectivity between its on-premises data center and AWS cloud resources, bypassing the public internet. Which AWS service provides this?
AWS VPN
AWS Direct Connect
AWS Transit Gateway
AWS PrivateLink
Rohan, a security analyst at a tech company, wants to detect cryptocurrency mining, brute-force SSH attempts, and unusual IAM activity across GCP resources in real time. Which Security Command Center (SCC) feature should he enable?
Security Health Analytics
Event Threat Detection
Container Threat Detection
Policy Analyzer
Samuel, a cloud engineer, configures network adapters with Single Root I/O Virtualization (SR-IOV) to give VMs direct access to the physical NIC, bypassing the hypervisor’s virtual switch. What is the main security concern with this setup?
Reduced performance for VM networking
Increased risk of VM-to-VM side-channel attacks
Lack of traffic inspection and monitoring at the hypervisor layer
Inability to support encrypted traffic
A SaaS company uses Google App Engine and configures firewall rules to restrict access. The security engineer learns that the platform enforces a limit on the number of rules that can be created. What is the impact of this limitation?
Only one firewall rule can exist for each application
Applications may require careful consolidation of firewall rules
Developers cannot secure App Engine applications at all
The rule limit applies only to outbound traffic
A healthcare provider wants to ensure that its GCP environment is continuously scanned for open firewall rules, exposed storage buckets, and weak IAM roles. Which Security Command Center (SCC) feature should be used?
Event Threat Detection
Security Health Analytics
Container Threat Detection
Cloud Logging
A media company needs to share large video files from Google Cloud Storage with customers using time-limited download links that expire after 24 hours. Which GCP feature supports this?
IAM Policy Analyzer
Signed URLs
Cloud CDN Cache Keys
Security Health Analytics
A university research team wants to share large datasets with external collaborators for 1 week, without creating accounts for every user. What is the best way to achieve this?
Use temporary, expiring links to share the datasets
Require all collaborators to create accounts
Send datasets via unsecured email attachments
Share datasets through public social media posts
An e-commerce site generates invoice PDFs for customers and delivers them using download links that expire in 1 hour. Which GCP feature should they configure?
Cloud CDN
Signed URLs
Signed Policy Documents
Cloud Identity Federation
A legal firm must allow external auditors to download case files securely from Google Cloud Storage, but only for 12 hours. Which feature should they enable?
Cloud VPN
GCP Signed URLs
Cloud Armor
Security Health Analytics
A healthcare provider stores sensitive medical data encrypted in cloud storage. After the retention period ends, the compliance officer requests secure deletion of the records. Instead of wiping the storage media, the security team deletes the encryption keys, making the data unreadable. Which secure deletion method is this?
Data Scrubbing
Nulling Out
Data Erasure
Crypto-Shredding
