wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

CompTIA Cloud+ Lesson 10 - Comprehending Security Compliance

Total questions: 87

Worksheet time: 44mins

Name
Class
Date
1.

Which of the following is listed as a data privacy concern impacting cloud security?

a)

Feature parity

b)

Tax reasons

c)

Server uptime SLAs

d)

Open-source licensing only

2.

An IT manager is mapping cloud risks to compliance obligations. Which category best addresses accountability for wrongdoing if data is mishandled?

a)

Legal punishment/culpability

b)

Industry best practices

c)

System performance tuning

d)

Marketing approvals

3.

You are advising a healthcare startup moving to the cloud. To reduce legal risks related to sector-specific rules, which concern should be prioritized first?

a)

Industry regulation

b)

Graphics processing speed

c)

Physical office access control only

d)

User interface theming

4.

A company experiences a data exposure incident in the cloud. Which listed concern most directly relates to protecting individuals’ information from unauthorized access?

a)

Tax reasons

b)

Privacy

c)

Log aggregation

d)

Beta feature testing

5.

Which role has full accountability and responsibility for organizational data?

a)

Data owner

b)

Data steward

c)

System administrator

d)

Network engineer

6.

What is the primary responsibility of a data steward?

a)

Setting legal policies for data

b)

Daily management and maintenance of data

c)

Auditing cross-border data transfers

d)

Owning full accountability for data

7.

Which statement best describes data residency?

a)

Ensuring data is processed quickly regardless of location

b)

Requiring data to follow laws where it is kept

c)

Controlling the geographic location where data is stored due to laws, tax rules, or policies

d)

Encrypting data before it leaves the organization

8.

An organization builds a cloud app that must keep all personal data created in Country X within its borders to meet national rules. Which concept is being applied?

a)

Data residency

b)

Data localization

c)

Data locality

d)

Data sovereignty

9.

A cloud architect places analytics clusters near the data they process to minimize latency and improve performance. Which concept does this illustrate?

a)

Data locality

b)

Data sovereignty

c)

Data residency

d)

Data stewardship

10.

A multinational company stores customer records in Region A and must follow Region A’s privacy and tax laws because the data is kept there. Which concept explains this requirement?

a)

Data localization

b)

Data sovereignty

c)

Data residency

d)

Data ownership

11.

Which statement best defines data classification in an organization?

a)

The process of encrypting all organizational data by default

b)

The process of labeling data to understand sensitivity and impact if exposed

c)

A legal requirement to store data only in on-premises servers

d)

A method for backing up data across multiple regions

12.

Which of the following is NOT an example label mentioned for data classification?

a)

Confidential

b)

Internal use only

c)

Public

d)

Export controlled

13.

Why do organizations use data classification labels such as confidential, internal use only, or public?

a)

To decide how to protect the data

b)

To ensure data is always shared publicly

c)

To avoid using cloud service providers

d)

To comply with software licensing

14.

Who provides tools that help label and manage data securely, according to the material?

a)

Internet Service Providers (ISPs)

b)

Cloud Service Providers (CSPs)

c)

Original Equipment Manufacturers (OEMs)

d)

Payment Card Networks

15.

What do data retention policies primarily specify?

a)

Only the encryption standards required for sensitive data

b)

How long information must be kept to follow legal, contractual, or regulatory rules

c)

The geographic location where data must be stored

d)

The exact server hardware needed to store archives

16.

In a typical retention policy, which time bounds may be set?

a)

Only a maximum time to delete data

b)

Only a minimum time to keep data

c)

A minimum time to keep data, and sometimes a maximum time after which it should not be stored

d)

No time bounds; retention is discretionary

17.

What is a litigation hold?

a)

A process that permanently deletes stale data to reduce storage costs

b)

A freeze on certain information because it might be needed in court, preventing deletion, change, or compression

c)

A mandate to move data to a cheaper storage tier

d)

An audit that verifies backup integrity monthly

18.

Which statement best defines data classification in an IT security context?

a)

Tagging data based on its sensitivity to guide protection strategies

b)

Encrypting all data by default regardless of sensitivity

c)

Deleting data after a fixed period of time

d)

Backing up data to multiple locations

19.

A company receives customer records from a partner. Which policy requires the receiving company to follow the sender’s specified retention rules?

a)

Regulatory hold

b)

Contractual hold

c)

Operational hold

d)

Litigation hold

20.

Which scenario illustrates a regulatory hold affecting data retention?

a)

A vendor agreement states logs must be kept for 2 years.

b)

A project team decides to keep emails for convenience.

c)

A national banking law mandates longer retention than local medical guidance.

d)

A cloud admin changes storage tiers to save costs.

21.

Which statement best defines a data retention policy?

a)

A guideline for encrypting data in transit only

b)

A set of rules specifying how long data must be kept and when it should be disposed of

c)

A checklist for selecting cloud providers

d)

A policy that only covers backup restoration procedures

22.

In a retention schedule, what do minimum and maximum retention times represent?

a)

The shortest and longest periods data must be stored before eligible deletion

b)

The fastest and slowest backup speeds

c)

The least and most secure encryption strengths

d)

The earliest and latest times users can access data each day

23.

Which scenario most appropriately requires a litigation hold?

a)

Data must be preserved because it might be relevant to an ongoing or anticipated lawsuit

b)

Data is needed to meet a marketing campaign deadline

c)

A system upgrade is scheduled for next quarter

d)

A vendor requests sample analytics data for benchmarking

24.

A contract with a client states that project records must be kept for seven years. What type of hold enforces this requirement?

a)

Litigation hold

b)

Contractual hold

c)

Regulatory hold

d)

Operational hold

25.

A healthcare provider must retain patient records for a legally mandated period set by law. What type of hold applies?

a)

Operational hold

b)

Contractual hold

c)

Regulatory hold

d)

Discretionary hold

26.

Which action is most appropriate when a regulatory or litigation hold conflicts with a policy’s maximum retention time?

a)

Purge the data at the maximum time to avoid storage costs

b)

Ignore the hold because policy takes precedence

c)

Suspend deletion and preserve the data until the hold is released

d)

Shorten the minimum retention time to compensate later

27.

Which statement best describes the purpose of SOC 2 in cloud environments?

a)

It sets rules for processing credit card transactions.

b)

It outlines controls for managing and protecting customer data based on trust service principles.

c)

It is a government law that mandates data localization in all regions.

d)

It certifies physical data center construction standards only.

28.

SOC 2 reports evaluate an organization against which set of principles?

a)

Confidentiality, availability, integrity, privacy, and security

b)

Performance, scalability, cost, and usability

c)

Encryption, antivirus, firewalls, and monitoring

d)

Recruitment, training, retention, and audits

29.

What is the primary difference between SOC 2 and SOC 3 reports?

a)

SOC 2 is public and high level; SOC 3 is restricted and detailed.

b)

SOC 2 focuses on physical security only; SOC 3 focuses on network security.

c)

SOC 2 provides detailed controls for auditors and customers; SOC 3 is a general-use summary for public audiences.

d)

SOC 2 is for on-premises systems; SOC 3 is only for cloud providers.

30.

A company wants a public-facing assurance to share on its website that it follows strong controls for security and privacy. Which report is most appropriate?

a)

SOC 1

b)

SOC 2 Type I

c)

SOC 2 Type II

d)

SOC 3

31.

Which scenario best demonstrates DoK 2 application of SOC 2 principles?

a)

Listing the five trust service principles from memory.

b)

Selecting controls that support availability and security for a new cloud API.

c)

Recalling that SOC 3 is intended for general audiences.

d)

Identifying that PCI DSS is unrelated to SOC.

32.

A cloud provider claims SOC 2 Type II compliance. What evidence should a customer expect this to represent?

a)

That the provider’s controls were designed effectively at a single point in time.

b)

That the provider complies with all government data protection laws globally.

c)

That the provider’s controls were designed and operated effectively over a period of time.

d)

That the provider only publishes a high-level summary report for marketing.

33.

Which industry standard specifically focuses on protecting cardholder data in organizations that handle payment card transactions?

a)

ISO 27001

b)

PCI DSS

c)

CSA STAR

d)

ISO 27005

34.

Within the ISO 27000 family, which standard defines the requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS)?

a)

ISO 27002

b)

ISO 27001

c)

ISO 27017

d)

ISO 27701

35.

What is the primary purpose of an Information Security Management System (ISMS) under ISO 27001?

a)

To enforce mandatory encryption on all systems

b)

To provide a systematic, risk-based framework for managing information security

c)

To certify cloud providers under a maturity model

d)

To replace all organization-specific security policies

36.

Which ISO 27000-series standard provides a code of practice with controls and guidance that complement ISO 27001’s ISMS requirements?

a)

ISO 27018

b)

ISO 27002

c)

ISO 27031

d)

ISO 27035

37.

Which organization leads the CSA STAR program and publishes cloud-specific security guidance and controls such as the Cloud Controls Matrix (CCM)?

a)

International Organization for Standardization

b)

Payment Card Industry Security Standards Council

c)

Cloud Security Alliance

d)

NIST

38.

An organization processes online payments and hosts customer data on a public cloud. To align with industry standards, which combined approach best addresses both payment security and cloud-specific control guidance?

a)

Implement ISO 27005 only

b)

Adopt PCI DSS and reference CSA Cloud Controls Matrix (CCM) guidance

c)

Use ISO 27701 exclusively

d)

Rely solely on ISO 27002 controls

39.

Which statement best defines the principle of least privilege in IT security?

a)

Grant users maximum access to encourage productivity

b)

Grant users only the minimum access necessary to perform their jobs

c)

Deny all access by default and never grant permissions

d)

Allow temporary contractors the same access as administrators

40.

An administrator is setting up access for a new help desk technician. Which action best applies the minimum access principle?

a)

Assign the technician full domain administrator rights to handle any issue

b)

Provide read-only access to all production databases regardless of role

c)

Grant permissions only to the ticketing system and tools required for troubleshooting

d)

Share a senior engineer’s account to avoid creating a new one

41.

Why does implementing least privilege reduce security risk?

a)

It ensures all users can modify any system settings, speeding response

b)

It limits the potential damage from compromised or misused accounts

c)

It removes the need for monitoring and auditing

d)

It prevents software from needing updates

42.

Which is the best example of applying access control aligned with least privilege?

a)

Developers receive production write access by default

b)

Finance staff can view but not alter HR records

c)

All employees are given local administrator rights on laptops

d)

Guests can access internal configuration portals after signing an NDA

43.

Which statement best defines Zero Trust Cloud Security?

a)

A model that automatically trusts internal devices once on the network

b)

A security approach that assumes no device or system is trusted by default and continuously verifies access

c)

A perimeter-focused model that trusts anything behind the firewall

d)

A compliance checklist used only for audit reporting

44.

Which core principle aligns most directly with the idea that user permissions should be limited to only what is necessary to perform tasks?

a)

Granular access controls

b)

Zero implicit trust

c)

Dynamic security

d)

Continuous authentication

45.

An organization wants to revalidate user identity and device health at frequent intervals during a session. Which Zero Trust principle is being applied?

a)

Granular access controls

b)

Continuous authentication

c)

Zero implicit trust

d)

Static security

46.

Which benefit of Zero Trust directly counters the assumption that anything inside the network is safe?

a)

Dynamic scaling

b)

Zero implicit trust

c)

Perimeter hardening

d)

Single sign-on

47.

Which statement about the Center for Internet Security (CIS) Benchmarks is accurate?

a)

They are tied to a single cloud vendor’s ecosystem

b)

They provide step-by-step guidance to securely configure servers, operating systems, and software

c)

They conflict with most other security standards

d)

They are suitable only for on‑premises environments

48.

A cloud team wants guidance specific to Azure. Which vendor-specific resource best fits this need?

a)

AWS Well‑Architected Framework Security Pillar

b)

Azure Security Benchmark

c)

Google Cloud Security Foundations Guide

d)

Oracle Cloud Security Best Practices

49.

What is the primary purpose of security benchmarks in IT?

a)

To add new features to systems

b)

To measure and standardize configurations that reduce security risk

c)

To replace antivirus software

d)

To eliminate the need for updates

50.

Which guideline set is produced by the U.S. Defense Information Systems Agency to define secure configurations for systems?

a)

CIS Benchmarks

b)

Vendor white papers

c)

STIGs

d)

ISO 9001

51.

CIS Benchmarks are commonly used for which of the following scenarios?

a)

Optimizing gaming performance

b)

Cloud security configurations across platforms like AWS, Azure, and Google Cloud

c)

Creating marketing analytics dashboards

d)

Managing physical access control only

52.

Vendor-specific security benchmarks are best described as:

a)

Generic guidelines applicable to any technology

b)

Compliance laws enforced by governments

c)

Configuration recommendations tailored to a specific product or platform by its manufacturer

d)

Informal tips shared on community forums

53.

You are tasked with securing a new Kubernetes cluster on a public cloud. Which benchmark would most directly guide baseline hardening across cloud providers?

a)

CIS Benchmarks

b)

STIG viewer templates only

c)

PCI DSS SAQ A

d)

COBIT maturity model

54.

A defense contractor must align Linux server configurations to requirements recognized by U.S. DoD programs. Which benchmark set is most appropriate?

a)

CIS Benchmarks

b)

Vendor marketing guides

c)

NIST CSF quick start

d)

STIGs

55.

An organization relies heavily on a specific database engine. To minimize misconfigurations unique to that product, which benchmark source should they prioritize?

a)

Vendor-specific security benchmark for that database

b)

General-purpose penetration testing checklist

c)

CIS Controls v8

d)

OWASP Top 10

56.

Which statement best compares STIGs and CIS Benchmarks for planning enterprise hardening?

a)

Both are entertainment standards with no security relevance

b)

STIGs target DoD-grade secure configurations; CIS Benchmarks provide widely adopted community standards including cloud-specific guidance

c)

CIS Benchmarks are only for mobile phones; STIGs only for routers

d)

STIGs focus on marketing while CIS Benchmarks are legal contracts

57.

Which statement best defines system hardening in the context of operating systems?

a)

Upgrading hardware components for better performance

b)

Reducing system weaknesses by applying secure configurations and controls

c)

Installing more applications to increase functionality

d)

Enabling all default accounts for easier access

58.

What is a primary risk of using an outdated or deprecated operating system?

a)

It consumes too much disk space

b)

It may no longer be supported and can contain unpatched security bugs

c)

It cannot run database software

d)

It forces use of open-source tools only

59.

Which set correctly expands the acronym LAMP in the context of baseline stacks?

a)

Linux, Apache, MySQL, PHP

b)

Linux, Ansible, MariaDB, Python

c)

Localhost, Apache, MariaDB, Perl

d)

Linux, Apache, MongoDB, PHP

60.

After establishing baseline settings, which tool is mentioned for automated configuration management to keep systems consistent and properly configured?

a)

iptables

b)

Ansible

c)

Nmap

d)

Docker

61.

Why should default accounts be deactivated or secured during OS hardening?

a)

They increase GPU usage

b)

They are often targeted by attackers and may have weak or well-known passwords

c)

They cannot be renamed

d)

They prevent software installation

62.

Which account is identified as the main Windows account with full control over the system?

a)

Guest

b)

Administrator

c)

Root

d)

User

63.

Which account is the main Linux account with complete system access and is commonly targeted during hardening steps?

a)

Guest

b)

Administrator

c)

Root

d)

Operator

64.

Which practice best describes a configuration baseline in system hardening?

a)

A fixed, unchangeable image used for all systems regardless of role

b)

A documented, approved starting set of settings that systems should conform to

c)

A temporary configuration used only during testing

d)

A backup of user data for disaster recovery

65.

What is the primary benefit of automated configuration management tools when enforcing baselines?

a)

They eliminate the need for human administrators entirely

b)

They continuously apply and verify settings at scale to maintain compliance

c)

They improve hardware performance by optimizing CPU usage

d)

They encrypt all network traffic by default

66.

Why should default accounts like Administrator, Guest, or root be deactivated or restricted?

a)

They consume excessive storage space

b)

They are widely known and commonly targeted by attackers

c)

They prevent software updates from installing

d)

They automatically expire after 30 days

67.

Which action aligns with securing privileged access under a baseline policy?

a)

Allow direct root or Administrator login over SSH/RDP for efficiency

b)

Use shared credentials for all admins to simplify auditing

c)

Require admins to log in with standard accounts and elevate privileges when needed

d)

Disable logging to reduce noise

68.

An organization wants every new server to start with the same hardened state, and drift from that state must be detected and corrected automatically. Which solution best fits this goal?

a)

Manual checklists executed quarterly

b)

Automated configuration management tied to an approved baseline

c)

Relying on vendor default images only

d)

Ad-hoc scripts run by each team as needed

69.

Which is the most appropriate handling of a built-in Guest account on production systems?

a)

Leave it enabled but rename it

b)

Disable or remove it and deny interactive logon

c)

Assign it to all contractors for temporary access

d)

Require multi-factor authentication on it while keeping it enabled

70.

What is the relationship between configuration baselines and auditing?

a)

Baselines replace the need for audits

b)

Auditing compares current configurations against the baseline to identify drift

c)

Auditing is only concerned with user activities, not configurations

d)

Baselines are created after an audit and never updated

71.

Which statement best distinguishes a baseline from a snapshot?

a)

A snapshot is an approved standard; a baseline is a point-in-time backup

b)

A baseline defines desired configuration state; a snapshot captures current state at a moment in time

c)

They are the same concept with different names

d)

A baseline is only for networking gear; a snapshot is only for servers

72.

Which statement best defines security patching in system hardening?

a)

Replacing all software with new versions regardless of risk

b)

Updating software or systems to fix weaknesses that attackers could exploit

c)

Disabling unused services to reduce the attack surface

d)

Encrypting all data at rest using full-disk encryption

73.

Why do many organizations first deploy patches in a test environment?

a)

To speed up installation across production systems

b)

To ensure updates don’t cause problems before reaching working systems

c)

To avoid using a centralized patching system

d)

To allow end users to approve updates

74.

What is the primary reason cipher suite deprecations occur?

a)

Newer hardware requires different port numbers

b)

Older suites are found to have weaknesses over time

c)

Operating systems stop supporting encryption

d)

Browsers cannot handle large keys

75.

Which organization provides guidance recommending current cipher suites and removal of outdated ones for U.S. government agencies?

a)

FCC

b)

NIST

c)

NSA

d)

DHS

76.

Which pair correctly lists common suites used to secure web traffic?

a)

IPsec and SSH

b)

TLS and SSL

c)

SCP and SFTP

d)

HTTPS and FTP

77.

A security engineer wants to eliminate the use of Telnet for administrative access. Which secure alternative should be required?

a)

SSH

b)

HTTP

c)

FTP

d)

RDP

78.

Which action best addresses the problem of unencrypted HTTP connections on a network?

a)

Enable Telnet for faster logins

b)

Limit HTTP and require HTTPS

c)

Replace TLS with SSL

d)

Use FTP for file transfers

79.

To encrypt traffic for legacy protocols that lack built-in encryption, which technology can be configured to cover all network protocols?

a)

RDP

b)

IPsec

c)

SCP

d)

FTPS

80.

What is the primary purpose of security patching?

a)

To add new hardware features

b)

To fix vulnerabilities and improve system security

c)

To increase user interface customization

d)

To reduce network bandwidth usage

81.

Which type of patch is typically an urgent, targeted fix released outside the regular update cycle to address a specific critical issue?

a)

Rollup

b)

Hotfix

c)

Signature update

d)

Service pack

82.

A web application firewall (WAF) rule is deployed to block an exploit until the developer can release code changes. What kind of patching approach is this?

a)

Hotfix

b)

Virtual patch

c)

Rollup

d)

Driver update

83.

Signature updates most directly help with which capability?

a)

Detecting known threats by pattern matching

b)

Restoring corrupted files from backup

c)

Upgrading operating system kernels

d)

Enforcing password rotation policies

84.

Which statement best describes a rollup?

a)

A cumulative package bundling multiple patches into a single update

b)

A test environment used before deployment

c)

A tool that creates digital signatures for binaries

d)

A method for reverting to a previous software version

85.

You need to apply a critical security fix with minimal downtime to a production server. Which option best fits this requirement?

a)

Schedule a quarterly rollup

b)

Wait for the next signature update

c)

Apply a hotfix

d)

Deploy a full OS upgrade

86.

Which is a best practice when applying security patches?

a)

Patch directly on production without testing

b)

Maintain an inventory and test patches in a staging environment before deployment

c)

Disable logging to speed up patching

d)

Only patch systems exposed to the internet

87.

An organization uses a WAF to block a zero-day exploit while waiting for the vendor’s official fix. What is the main risk if they rely on this approach long term?

a)

Virtual patches may not cover all attack vectors and can be bypassed

b)

Hotfixes always require system reboots

c)

Rollups cannot be uninstalled

d)

Signature updates will delete legitimate traffic