wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Modules 9-11

Total questions: 70

Worksheet time: 35mins

Name
Class
Date
1.

A global e-commerce company wants users in Europe to be directed to servers in the EU region, while users in North America connect to servers in the U.S. Which Route 53 feature should be configured?

a)

Latency-Based Routing

b)

Weighted Routing

c)

Geolocation Routing

d)

Failover Routing

2.

A media company wants to restrict video streaming so that only users in the United States and Canada can access their service. Which Route 53 feature should be used?

a)

Latency-Based Routing

b)

Failover Routing

c)

Geolocation Routing

d)

Multivalue Answer Routing

3.

A European financial services company must ensure EU customer DNS queries resolve only to EU-based servers to meet GDPR requirements. Which routing policy enforces this compliance?

a)

Weighted Routing

b)

Latency-Based Routing

c)

Geolocation Routing

d)

Simple Routing

4.

An e-commerce company wants customers in Asia redirected to a region-specific site that displays local promotions and prices. Which routing option should be configured?

a)

Geolocation Routing

b)

Weighted Routing

c)

Geolocation Routing

d)

Failover Routing

5.

A company called TechGlobal sets up Route 53 Geolocation Routing for the U.S., Europe, and Asia. Mia, a user from South America, tries to access the site but is not mapped. What happens?

a)

The request is denied

b)

The request follows the default rule set in Route 53

c)

The request randomly chooses between U.S. or Europe

d)

The request always resolves to the nearest data center

6.

A multinational retailer uses Route 53 Geolocation Routing. If a primary region becomes unavailable, how can DNS still direct traffic to backup servers?

a)

Use Weighted Routing

b)

Combine Geolocation Routing with Failover Routing

c)

Switch to Latency-Based Routing

d)

Disable Geolocation during outages

7.

Anika is working for a government agency that requires DNS records in Route 53 to be cryptographically validated to prevent cache poisoning and spoofing attacks. Which feature should she enable?

a)

DNS Failover

b)

DNSSEC

c)

Geolocation Routing

d)

Health Checks

8.

A multinational corporation hosts a high-profile web app prone to Layer 7 attacks. The security team wants real-time DDoS cost protection, detailed attack diagnostics, and 24/7 AWS support. Which AWS service tier should they use?

a)

AWS Shield Standard

b)

AWS Shield Advanced

c)

AWS WAF Basic

d)

GuardDuty

9.

A financial firm needs to identify DNS queries from compromised machines trying to exfiltrate data. Which AWS feature provides query logging for DNS requests?

a)

Route 53 Resolver Query Logging

b)

CloudTrail Insights

c)

VPC Flow Logs

d)

CloudWatch Alarms

10.

A SaaS provider uses both AWS and Azure to host services. They want a DNS solution that ensures low-latency, multi-cloud global failover across both providers. Which approach is most effective?

a)

Configure only AWS Route 53

b)

Configure only Azure Traffic Manager

c)

Use a third-party DNS provider with multi-cloud support

d)

Configure DNS records manually across both platforms

11.

During a DDoS attack, a retailer notices AWS WAF rate-limiting blocks some legitimate flash-sale traffic along with malicious requests. How should this be mitigated?

a)

Disable WAF during sales events

b)

Tune rate-limiting thresholds and use Shield Advanced with granular rules

c)

Switch to manual firewall management

d)

Block all overseas traffic by default

12.

An e-commerce company wants DNS to direct users to the nearest regional server to minimize latency. Which Route 53 routing policy should they use?

a)

Geolocation routing policy

b)

Weighted routing policy

c)

Failover routing policy

d)

Simple routing policy

13.

William is setting up a global website and wants to ensure that users are always directed to the server region with the lowest network delay. Which routing policy should William use to achieve this?

a)

Geolocation Routing

b)

Latency-Based Routing

c)

Weighted Routing

d)

Multivalue Answer Routing

14.

Kai is managing a hybrid IT environment where AWS Route 53 is used for public DNS and Microsoft Active Directory DNS is used for internal workloads. The team wants to prevent DNS spoofing and exfiltration between the two systems. Which practice is most effective?

a)

Enable DNSSEC for public zones and monitor DNS Resolver logs internally

b)

Disable Route 53 for public DNS

c)

Rely only on firewall filtering between on-prem and cloud

d)

Allow unrestricted DNS queries to reduce latency

15.

A DevSecOps team is adopting Infrastructure as Code (IaC) to deploy resources across AWS and Azure. They want to automatically detect misconfigured security groups, public S3 buckets, and non-compliant IAM roles before deployment. Which approach should they use?

a)

Manual peer review of all IaC templates

b)

Automated IaC scanning with policy-as-code tools

c)

CloudTrail API activity logging

d)

Penetration testing after deployment

16.

Avery is a security engineer at a tech company. She wants to continuously check the company's AWS EC2 instances and container workloads for CVE vulnerabilities, exposed ports, and misconfigured IAM roles. Which AWS service should she enable?

a)

AWS GuardDuty

b)

AWS Security Hub

c)

AWS Inspector

d)

AWS Config

17.

Grace, a member of a cloud infrastructure team, enables Single Root I/O Virtualization (SR-IOV) on virtual machines in her company’s data center. This allows the VMs to have direct access to the physical NIC, bypassing the hypervisor’s virtual switch. What is the main operational benefit of this configuration?

a)

Improved network performance and lower latency

b)

Enhanced data encryption between VMs

c)

Automatic backup of network configurations

d)

Increased virtual machine storage capacity

18.

Aria is setting up a cloud environment for her company and is considering different technologies to optimize network performance. Which of the following is a benefit of using SR-IOV in this scenario?

a)

Reduced network latency and improved throughput

b)

Increased hypervisor monitoring visibility

c)

Automatic DDoS mitigation at the hypervisor layer

d)

Easier cross-VM traffic inspection

19.

A financial institution wants to automatically check for open firewall rules, public Cloud Storage buckets, and excessive IAM permissions in Google Cloud. Which feature should they enable in Security Command Center (SCC)?

a)

Event Threat Detection

b)

Security Health Analytics

c)

Forseti Scanner

d)

Cloud Armor

20.

A multinational company wants to reduce shadow IT risks by automatically identifying and shutting down cloud resources provisioned outside approved governance policies. Which approach is most effective?

a)

Manual quarterly audits of cloud accounts

b)

Enforcing automation via cloud governance frameworks and policy-as-code

c)

Training developers to avoid unauthorized deployments

d)

Relying on incident response teams to catch issues post-deployment

21.

During an annual disaster recovery (DR) test at a healthcare provider, engineers discover that after an automated failover to a secondary region, certain IAM policies and backup configurations are missing from the recovery environment. What does this reveal?

a)

The DR plan fully meets compliance requirements

b)

The DR plan has operational gaps requiring review and updates

c)

The DR environment provides better performance than production

d)

The DR plan should be replaced with manual failover procedures

22.

A financial institution is migrating legacy applications to the cloud. The security team wants to ensure that current security controls, compliance standards, and operational processes are not weakened during migration. Which step should they take first?

a)

Conduct a gap analysis between existing security posture and cloud security requirements

b)

Begin migration immediately and address issues post-deployment

c)

Outsource the entire migration to a managed service provider

d)

Deploy workloads in multiple regions without review

23.

Aria, a healthcare provider, is evaluating a third-party SaaS vendor for patient data storage. To ensure compliance with HIPAA, which action should she prioritize before procurement?

a)

Perform a gap analysis of vendor security controls against compliance requirements

b)

Assume vendor compliance since they operate in the cloud

c)

Review the vendor’s marketing material for security claims

d)

Wait until after contract signing to evaluate controls

24.

A retail company wants to automatically detect and remediate non-compliant S3 buckets that are publicly accessible. Which AWS service can enforce these compliance rules automatically?

a)

AWS GuardDuty

b)

AWS Inspector

c)

AWS Config with custom rules and remediation actions

d)

AWS Security Hub

25.

Scarlett, an auditor at a large company, requests evidence of all IAM role changes over the past 90 days. Which AWS service provides historical configuration data?

a)

AWS CloudTrail

b)

AWS Security Hub

c)

AWS Config

d)

Amazon Macie

26.

A financial services company must ensure that all EC2 instances are tagged with Owner and Environment keys before deployment. Which AWS service can automatically enforce this policy?

a)

AWS Config

b)

AWS CloudTrail

c)

AWS Inspector

d)

AWS Trusted Advisor

27.

Arjun, a cloud engineer at a growing tech company, needs to automatically identify and remediate security groups that allow unrestricted inbound SSH (0.0.0.0/0:22). Which service is best suited for this?

a)

AWS Config with managed rule and remediation actions

b)

AWS WAF

c)

AWS CloudTrail

d)

AWS Shield

28.

Noah, a forensic analyst, is investigating a security breach and creates an EBS snapshot of a compromised EC2 instance. Which best practice ensures the snapshot can be used as evidence in court?

a)

Store the snapshot in a public S3 bucket for transparency

b)

Apply encryption and maintain a strict chain of custody

c)

Use the snapshot immediately for patch testing

d)

Modify the snapshot to remove malicious files before analysis

29.

Sophia is a cloud vendor who wants to demonstrate alignment with industry-standard security controls and publish her company's security posture for customers to review. Which framework and registry should Sophia use?

a)

NIST CSF and FedRAMP Marketplace

b)

CSA CCM and STAR Registry

c)

ISO 9001 and ITIL Service Catalog

d)

MITRE ATT&CK and CVE Registry

30.

Harper, a member of a security team, suspects data exfiltration from an EC2 instance in their AWS environment. Which AWS feature provides visibility into IP traffic flow metadata to support breach investigation?

a)

AWS CloudTrail

b)

AWS Config

c)

AWS VPC Flow Logs

d)

AWS GuardDuty

31.

James is working for a company that is worried about being unable to migrate their workloads from one cloud provider to another because of proprietary APIs and service dependencies. What is this risk called?

a)

Cloud Interoperability

b)

Vendor Lock-In

c)

Multi-Cloud Resilience

d)

Data Portability

32.

Arjun is working at a company that provides cloud services to various clients. His responsibilities include overseeing cloud service operations, managing SLAs, and ensuring the delivery of services to customers. According to the NIST Cloud Reference Architecture, which role does Arjun fulfill?

a)

Cloud Auditor

b)

Cloud Service Manager

c)

Cloud Broker

d)

Cloud Carrier

33.

During a security incident in Google Cloud, Maya is assigned to coordinate response efforts, make final decisions, and communicate with executives. Which role is this?

a)

Security Incident Analyst

b)

Security Incident Commander

c)

Cloud Operations Lead
Forensic Investigator

d)

Forensic Investigator

34.

Emma is part of a security team at a company that is planning to migrate its workloads to the cloud. Before starting the migration, the company needs to ensure its current security controls and compliance requirements are aligned with the cloud provider's capabilities. Which step should Emma and her team perform?

a)

Conduct a gap analysis between current posture and cloud security requirements

b)

Begin migration immediately and fix issues after deployment

c)

Outsource the migration fully to a third-party MSP

d)

Rely on provider default security settings

35.

A healthcare company is evaluating a SaaS vendor to handle patient data. To ensure HIPAA compliance, what should be performed before procurement?

a)

Gap analysis of vendor controls against compliance requirements

b)

Assume vendor compliance because they are a cloud provider

c)

Review marketing material for vendor security claims

d)

Evaluate security only after signing the contract

36.

Zoe's company is planning to use several cloud services from different providers. She needs help selecting the right services, negotiating contracts, and managing the company's usage across all these providers. In the NIST Cloud Reference Architecture, which role would assist Zoe with these tasks?

a)

Cloud Consumer

b)

Cloud Service Broker

c)

Cloud Service Manager

d)

Cloud Auditor

37.

Charlotte is leading a company's migration of workloads to AWS. She wants a structured approach that covers areas like people, governance, operations, and security. Which framework should she follow?

a)

NIST Cybersecurity Framework

b)

AWS Cloud Adoption Framework (CAF)

c)

CSA Cloud Controls Matrix (CCM)

d)

ITIL Service Management Framework

38.

A forensic investigator needs to share an Azure VM snapshot with an external incident response team. The access should be temporary and limited to read-only use. Which Azure feature should be applied?

a)

Role-Based Access Control (RBAC)

b)

Shared Access Signature (SAS)

c)

Azure Policy Assignment

d)

Azure Security Center

39.

During a red-team engagement, Aiden is tasked with assessing the security of a company's cloud infrastructure. Aiden enumerates cloud resources by accessing metadata services and exposed APIs. What type of activity is this?

a)

Cloud Reconnaissance

b)

Data Exfiltration

c)

Privilege Escalation

d)

Persistence

40.

Samuel is leading a team to improve their organization's cybersecurity posture. He mentions that NIST CSF is ________-centric, not a full migration framework. What does he mean?

a)

Security

b)

Data

c)

Cloud

d)

Application

41.

Charlotte is leading a cloud security project and comes across the CSA CCM. She needs to explain to her team that CSA CCM is a ________ matrix, not migration guidance.

a)

Control

b)

Migration

c)

Security

d)

Compliance

42.

Olivia is leading an IT team and wants to implement best practices for managing their IT services. She learns that ITIL is focused on IT service management, not ________ adoption.

a)

cloud

b)

hardware

c)

software

d)

network

43.

William is the IT security manager at an enterprise that uses multiple cloud providers. He wants to ensure that security policies remain consistent across all these environments. Which NIST recommendation addresses the need for homogeneity in operations?

a)

A. Standardized security baselines across providers

b)

B. Relying only on native tools from each CSP

c)

C. Outsourcing all operations to a managed service provider

d)

D. Enforcing manual compliance audits quarterly

44.

A forensic team led by Mason acquires evidence from a compromised EC2 instance during a corporate security breach investigation. Which step ensures the evidence remains admissible and defensible in an investigation?

a)

Modify the disk image to remove malicious files

b)

Document hash values and chain of custody records

c)

Perform vulnerability patching before acquisition

d)

Store the evidence only on the analyst’s laptop

45.

William is leading a digital transformation initiative at a large enterprise, and the company decides to establish a Cloud Center of Excellence (CCoE). What is the primary function of this CCoE?

a)

Acting as a tactical incident response team

b)

Managing daily backups and restores

c)

Standardizing governance, best practices, and cloud adoption strategy

d)

Serving as a regulatory compliance auditor

46.

Mason, a forensic analyst, takes a snapshot of a compromised Azure VM for evidence. Before mounting the snapshot to another VM, which precaution should be taken?

a)

Encrypt the snapshot and make a copy before mounting

b)

Patch the VM image to remove malicious code before mounting

c)

Modify file timestamps to simplify review

d)

Share the snapshot publicly to improve analysis collaboration

47.

During a major security breach in a company's cloud infrastructure, Nora receives an alert about unauthorized access. Who should act as the first responder to contain and mitigate the incident?

a)

System Administrators

b)

Cloud Incident Handlers

c)

Executive Leadership

d)

Cloud Service Customers

48.

Michael, the CIO of a large corporation, leads an initiative to implement a cloud governance framework. The goal is to balance security, cost management, and innovation across various stakeholders in the company. What is the primary purpose of this governance?

a)

To enforce operational silos between business units

b)

To align cloud strategy with corporate objectives and stakeholder needs

c)

To restrict developers from deploying resources

d)

To replace compliance with agility

49.

A financial services firm requires a DR solution with near real-time replication and the ability to fail over within minutes, but at a lower cost than full hot-site redundancy. Which approach should be used?

a)

Pilot Light

b)

Backup and Restore

c)

Warm Standby

d)

Active-Active Hot Site

50.

Samuel, the IT manager at a large enterprise, is concerned about employees provisioning unauthorized cloud services, which could introduce security risks. Which governance practice would be most effective for Samuel to implement?

a)

Quarterly manual audits of expense reports

b)

Implementing policy-as-code with automated enforcement across accounts

c)

Blocking all developer access to cloud resources

d)

Allowing shadow IT but monitoring it passively

51.

A healthcare company conducts an annual disaster recovery (DR) plan test and discovers that several applications cannot fail over within the required recovery time objectives (RTOs). What does this indicate?

a)

The DR plan is fully compliant with objectives

b)

The DR plan requires updates to close operational gaps

c)

The DR plan should be abandoned in favor of manual recovery

d)

The DR test should only be performed after an actual disaster

52.

During an active cloud breach, the security team isolates affected EC2 instances, blocks malicious IPs, and revokes compromised credentials. Which phase of the incident response lifecycle are they performing?

a)

Preparation

b)

Containment

c)

Recovery

d)

Post-Incident Review

53.

A global enterprise wants to establish a certified Information Security Management System (ISMS) for cloud operations and apply detailed control guidance. Which standards should they adopt?

a)

ISO 27001 and ISO 27002

b)

ISO 9001 and ISO 14001

c)

NIST SP 800-53 and FedRAMP

d)

ITIL and COBIT

54.

A financial firm discovers during DR testing that backup systems fail when switching from primary to warm standby sites. Which maturity improvement should be prioritized?

a)

Implement better SLAs with cloud providers

b)

Conduct more frequent DR drills and validate failover automation

c)

Replace warm standby with manual backup tapes

d)

Disable failover to avoid future test failures

55.

An organization uses SOAR (Security Orchestration, Automation, and Response) to automatically quarantine infected workloads and rotate IAM credentials when compromise is detected. Which IR phase is being automated?

a)

Eradication

b)

Containment

c)

Recovery

d)

Preparation

56.

An online retailer wants a DR solution where a scaled-down version of production is always running in another region. In case of disaster, workloads can scale up quickly with minimal downtime. Which strategy best fits this requirement?

a)

Backup and Restore

b)

Warm Standby

c)

Active-Active Multi-Region

d)

Pilot Light

57.

An enterprise wants to eliminate unauthorized cloud services provisioned outside IT governance. Which control is most effective?

a)

Policy-as-Code with continuous enforcement

b)

Quarterly manual shadow IT reviews

c)

Blocking all internet access for developers

d)

Training staff to self-report shadow IT services

58.

A financial services firm chooses a DR approach where infrastructure and network resources are pre-provisioned, but applications and data need to be restored before use. Which option does this describe?

a)

Backup and Restore

b)

Warm Standby

c)

Active-Active Multi-Region

d)

Pilot Light

59.

Which of the following recovery site types includes pre-configured infrastructure, enabling faster recovery than a cold site but slower than a hot site?

a)

Hot Site

b)

Warm Site

c)

Cold Site

d)

Backup and Restore

60.

During a scheduled DR exercise, an organization discovers that replication lag prevents certain RDS databases from meeting Recovery Point Objectives (RPOs). What does this finding indicate?

a)

The DR plan is fully effective

b)

The DR plan has gaps and requires tuning of replication processes

c)

RPO objectives should be removed from the DR plan

d)

Database backups should be disabled during testing

61.

During an ongoing attack, a cloud provider’s IR team automatically isolates compromised Kubernetes pods, blocks malicious IP addresses, and revokes leaked credentials. Which IR phase is this?

a)

Preparation

b)

Containment

c)

Eradication

d)

Recovery

62.

A global SaaS provider experiences a data breach. Which team should act as the first responder to preserve evidence and begin containment?

a)

Executive Leadership

b)

Cloud Incident Handlers

c)

End Users

d)

Cloud Auditors

63.

A corporation’s board mandates that cloud governance must balance security, financial efficiency, and innovation. What is the main outcome of this governance process?

a)

Restricting developers from using cloud services

b)

Aligning stakeholder interests with enterprise cloud strategy

c)

Allowing each business unit to define its own security controls independently

d)

Reducing compliance oversight to accelerate innovation

64.

An insurance provider selects a DR approach where partial infrastructure is always running in another region, allowing workloads to scale rapidly in case of disaster. Which strategy does this describe?

a)

Pilot Light

b)

Warm Standby

c)

Backup and Restore

d)

Hot Site

65.

A multinational enterprise identifies employees using unauthorized SaaS applications. Which governance approach provides real-time prevention of shadow IT?

a)

Quarterly manual reviews

b)

Security training programs

c)

Policy-as-Code automation across cloud accounts

d)

Blocking all developer access

66.

A cloud provider wants to align with international standards for ISMS certification and detailed security controls. Which ISO standards should they adopt?

a)

ISO 27001 and ISO 27002

b)

ISO 9001 and ISO 22301

c)

NIST SP 800-53 and FedRAMP

d)

COBIT and ITIL

67.

During a ransomware attack in the cloud, who should perform the initial containment and evidence preservation?

a)

End Users

b)

Cloud Incident Handlers

c)

Cloud Auditors

d)

Executive Management

68.

An enterprise defines a governance model to balance security, compliance, and business innovation. What is the outcome?

a)

Restricting developer activity entirely

b)

Alignment of stakeholder priorities with cloud strategy

c)

Delegation of governance to individual teams with no oversight

d)

Removal of compliance controls for faster deployment

69.

A media company requires a DR solution that provides partial infrastructure always running, capable of scaling up quickly. Which DR approach matches this need?

a)

Backup and Restore

b)

Pilot Light

c)

Warm Standby

d)

Active-Active Hot Site

70.

A global bank wants to prevent employees from provisioning unauthorized SaaS apps. Which governance strategy is most effective?

a)

Quarterly manual governance audits

b)

Policy-as-Code enforcement across accounts