Font size
WorksheetsCompTIA Cloud+ Lesson 10 - Comprehending Security Compliance
Total questions: 87
Worksheet time: 44mins
Which of the following is listed as a data privacy concern impacting cloud security?
Feature parity
Tax reasons
Server uptime SLAs
Open-source licensing only
An IT manager is mapping cloud risks to compliance obligations. Which category best addresses accountability for wrongdoing if data is mishandled?
Legal punishment/culpability
Industry best practices
System performance tuning
Marketing approvals
You are advising a healthcare startup moving to the cloud. To reduce legal risks related to sector-specific rules, which concern should be prioritized first?
Industry regulation
Graphics processing speed
Physical office access control only
User interface theming
A company experiences a data exposure incident in the cloud. Which listed concern most directly relates to protecting individuals’ information from unauthorized access?
Tax reasons
Privacy
Log aggregation
Beta feature testing
Which role has full accountability and responsibility for organizational data?
Data owner
Data steward
System administrator
Network engineer
What is the primary responsibility of a data steward?
Setting legal policies for data
Daily management and maintenance of data
Auditing cross-border data transfers
Owning full accountability for data
Which statement best describes data residency?
Ensuring data is processed quickly regardless of location
Requiring data to follow laws where it is kept
Controlling the geographic location where data is stored due to laws, tax rules, or policies
Encrypting data before it leaves the organization
An organization builds a cloud app that must keep all personal data created in Country X within its borders to meet national rules. Which concept is being applied?
Data residency
Data localization
Data locality
Data sovereignty
A cloud architect places analytics clusters near the data they process to minimize latency and improve performance. Which concept does this illustrate?
Data locality
Data sovereignty
Data residency
Data stewardship
A multinational company stores customer records in Region A and must follow Region A’s privacy and tax laws because the data is kept there. Which concept explains this requirement?
Data localization
Data sovereignty
Data residency
Data ownership
Which statement best defines data classification in an organization?
The process of encrypting all organizational data by default
The process of labeling data to understand sensitivity and impact if exposed
A legal requirement to store data only in on-premises servers
A method for backing up data across multiple regions
Which of the following is NOT an example label mentioned for data classification?
Confidential
Internal use only
Public
Export controlled
Why do organizations use data classification labels such as confidential, internal use only, or public?
To decide how to protect the data
To ensure data is always shared publicly
To avoid using cloud service providers
To comply with software licensing
Who provides tools that help label and manage data securely, according to the material?
Internet Service Providers (ISPs)
Cloud Service Providers (CSPs)
Original Equipment Manufacturers (OEMs)
Payment Card Networks
What do data retention policies primarily specify?
Only the encryption standards required for sensitive data
How long information must be kept to follow legal, contractual, or regulatory rules
The geographic location where data must be stored
The exact server hardware needed to store archives
In a typical retention policy, which time bounds may be set?
Only a maximum time to delete data
Only a minimum time to keep data
A minimum time to keep data, and sometimes a maximum time after which it should not be stored
No time bounds; retention is discretionary
What is a litigation hold?
A process that permanently deletes stale data to reduce storage costs
A freeze on certain information because it might be needed in court, preventing deletion, change, or compression
A mandate to move data to a cheaper storage tier
An audit that verifies backup integrity monthly
Which statement best defines data classification in an IT security context?
Tagging data based on its sensitivity to guide protection strategies
Encrypting all data by default regardless of sensitivity
Deleting data after a fixed period of time
Backing up data to multiple locations
A company receives customer records from a partner. Which policy requires the receiving company to follow the sender’s specified retention rules?
Regulatory hold
Contractual hold
Operational hold
Litigation hold
Which scenario illustrates a regulatory hold affecting data retention?
A vendor agreement states logs must be kept for 2 years.
A project team decides to keep emails for convenience.
A national banking law mandates longer retention than local medical guidance.
A cloud admin changes storage tiers to save costs.
Which statement best defines a data retention policy?
A guideline for encrypting data in transit only
A set of rules specifying how long data must be kept and when it should be disposed of
A checklist for selecting cloud providers
A policy that only covers backup restoration procedures
In a retention schedule, what do minimum and maximum retention times represent?
The shortest and longest periods data must be stored before eligible deletion
The fastest and slowest backup speeds
The least and most secure encryption strengths
The earliest and latest times users can access data each day
Which scenario most appropriately requires a litigation hold?
Data must be preserved because it might be relevant to an ongoing or anticipated lawsuit
Data is needed to meet a marketing campaign deadline
A system upgrade is scheduled for next quarter
A vendor requests sample analytics data for benchmarking
A contract with a client states that project records must be kept for seven years. What type of hold enforces this requirement?
Litigation hold
Contractual hold
Regulatory hold
Operational hold
A healthcare provider must retain patient records for a legally mandated period set by law. What type of hold applies?
Operational hold
Contractual hold
Regulatory hold
Discretionary hold
Which action is most appropriate when a regulatory or litigation hold conflicts with a policy’s maximum retention time?
Purge the data at the maximum time to avoid storage costs
Ignore the hold because policy takes precedence
Suspend deletion and preserve the data until the hold is released
Shorten the minimum retention time to compensate later
Which statement best describes the purpose of SOC 2 in cloud environments?
It sets rules for processing credit card transactions.
It outlines controls for managing and protecting customer data based on trust service principles.
It is a government law that mandates data localization in all regions.
It certifies physical data center construction standards only.
SOC 2 reports evaluate an organization against which set of principles?
Confidentiality, availability, integrity, privacy, and security
Performance, scalability, cost, and usability
Encryption, antivirus, firewalls, and monitoring
Recruitment, training, retention, and audits
What is the primary difference between SOC 2 and SOC 3 reports?
SOC 2 is public and high level; SOC 3 is restricted and detailed.
SOC 2 focuses on physical security only; SOC 3 focuses on network security.
SOC 2 provides detailed controls for auditors and customers; SOC 3 is a general-use summary for public audiences.
SOC 2 is for on-premises systems; SOC 3 is only for cloud providers.
A company wants a public-facing assurance to share on its website that it follows strong controls for security and privacy. Which report is most appropriate?
SOC 1
SOC 2 Type I
SOC 2 Type II
SOC 3
Which scenario best demonstrates DoK 2 application of SOC 2 principles?
Listing the five trust service principles from memory.
Selecting controls that support availability and security for a new cloud API.
Recalling that SOC 3 is intended for general audiences.
Identifying that PCI DSS is unrelated to SOC.
A cloud provider claims SOC 2 Type II compliance. What evidence should a customer expect this to represent?
That the provider’s controls were designed effectively at a single point in time.
That the provider complies with all government data protection laws globally.
That the provider’s controls were designed and operated effectively over a period of time.
That the provider only publishes a high-level summary report for marketing.
Which industry standard specifically focuses on protecting cardholder data in organizations that handle payment card transactions?
ISO 27001
PCI DSS
CSA STAR
ISO 27005
Within the ISO 27000 family, which standard defines the requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS)?
ISO 27002
ISO 27001
ISO 27017
ISO 27701
What is the primary purpose of an Information Security Management System (ISMS) under ISO 27001?
To enforce mandatory encryption on all systems
To provide a systematic, risk-based framework for managing information security
To certify cloud providers under a maturity model
To replace all organization-specific security policies
Which ISO 27000-series standard provides a code of practice with controls and guidance that complement ISO 27001’s ISMS requirements?
ISO 27018
ISO 27002
ISO 27031
ISO 27035
Which organization leads the CSA STAR program and publishes cloud-specific security guidance and controls such as the Cloud Controls Matrix (CCM)?
International Organization for Standardization
Payment Card Industry Security Standards Council
Cloud Security Alliance
NIST
An organization processes online payments and hosts customer data on a public cloud. To align with industry standards, which combined approach best addresses both payment security and cloud-specific control guidance?
Implement ISO 27005 only
Adopt PCI DSS and reference CSA Cloud Controls Matrix (CCM) guidance
Use ISO 27701 exclusively
Rely solely on ISO 27002 controls
Which statement best defines the principle of least privilege in IT security?
Grant users maximum access to encourage productivity
Grant users only the minimum access necessary to perform their jobs
Deny all access by default and never grant permissions
Allow temporary contractors the same access as administrators
An administrator is setting up access for a new help desk technician. Which action best applies the minimum access principle?
Assign the technician full domain administrator rights to handle any issue
Provide read-only access to all production databases regardless of role
Grant permissions only to the ticketing system and tools required for troubleshooting
Share a senior engineer’s account to avoid creating a new one
Why does implementing least privilege reduce security risk?
It ensures all users can modify any system settings, speeding response
It limits the potential damage from compromised or misused accounts
It removes the need for monitoring and auditing
It prevents software from needing updates
Which is the best example of applying access control aligned with least privilege?
Developers receive production write access by default
Finance staff can view but not alter HR records
All employees are given local administrator rights on laptops
Guests can access internal configuration portals after signing an NDA
Which statement best defines Zero Trust Cloud Security?
A model that automatically trusts internal devices once on the network
A security approach that assumes no device or system is trusted by default and continuously verifies access
A perimeter-focused model that trusts anything behind the firewall
A compliance checklist used only for audit reporting
Which core principle aligns most directly with the idea that user permissions should be limited to only what is necessary to perform tasks?
Granular access controls
Zero implicit trust
Dynamic security
Continuous authentication
An organization wants to revalidate user identity and device health at frequent intervals during a session. Which Zero Trust principle is being applied?
Granular access controls
Continuous authentication
Zero implicit trust
Static security
Which benefit of Zero Trust directly counters the assumption that anything inside the network is safe?
Dynamic scaling
Zero implicit trust
Perimeter hardening
Single sign-on
Which statement about the Center for Internet Security (CIS) Benchmarks is accurate?
They are tied to a single cloud vendor’s ecosystem
They provide step-by-step guidance to securely configure servers, operating systems, and software
They conflict with most other security standards
They are suitable only for on‑premises environments
A cloud team wants guidance specific to Azure. Which vendor-specific resource best fits this need?
AWS Well‑Architected Framework Security Pillar
Azure Security Benchmark
Google Cloud Security Foundations Guide
Oracle Cloud Security Best Practices
What is the primary purpose of security benchmarks in IT?
To add new features to systems
To measure and standardize configurations that reduce security risk
To replace antivirus software
To eliminate the need for updates
Which guideline set is produced by the U.S. Defense Information Systems Agency to define secure configurations for systems?
CIS Benchmarks
Vendor white papers
STIGs
ISO 9001
CIS Benchmarks are commonly used for which of the following scenarios?
Optimizing gaming performance
Cloud security configurations across platforms like AWS, Azure, and Google Cloud
Creating marketing analytics dashboards
Managing physical access control only
Vendor-specific security benchmarks are best described as:
Generic guidelines applicable to any technology
Compliance laws enforced by governments
Configuration recommendations tailored to a specific product or platform by its manufacturer
Informal tips shared on community forums
You are tasked with securing a new Kubernetes cluster on a public cloud. Which benchmark would most directly guide baseline hardening across cloud providers?
CIS Benchmarks
STIG viewer templates only
PCI DSS SAQ A
COBIT maturity model
A defense contractor must align Linux server configurations to requirements recognized by U.S. DoD programs. Which benchmark set is most appropriate?
CIS Benchmarks
Vendor marketing guides
NIST CSF quick start
STIGs
An organization relies heavily on a specific database engine. To minimize misconfigurations unique to that product, which benchmark source should they prioritize?
Vendor-specific security benchmark for that database
General-purpose penetration testing checklist
CIS Controls v8
OWASP Top 10
Which statement best compares STIGs and CIS Benchmarks for planning enterprise hardening?
Both are entertainment standards with no security relevance
STIGs target DoD-grade secure configurations; CIS Benchmarks provide widely adopted community standards including cloud-specific guidance
CIS Benchmarks are only for mobile phones; STIGs only for routers
STIGs focus on marketing while CIS Benchmarks are legal contracts
Which statement best defines system hardening in the context of operating systems?
Upgrading hardware components for better performance
Reducing system weaknesses by applying secure configurations and controls
Installing more applications to increase functionality
Enabling all default accounts for easier access
What is a primary risk of using an outdated or deprecated operating system?
It consumes too much disk space
It may no longer be supported and can contain unpatched security bugs
It cannot run database software
It forces use of open-source tools only
Which set correctly expands the acronym LAMP in the context of baseline stacks?
Linux, Apache, MySQL, PHP
Linux, Ansible, MariaDB, Python
Localhost, Apache, MariaDB, Perl
Linux, Apache, MongoDB, PHP
After establishing baseline settings, which tool is mentioned for automated configuration management to keep systems consistent and properly configured?
iptables
Ansible
Nmap
Docker
Why should default accounts be deactivated or secured during OS hardening?
They increase GPU usage
They are often targeted by attackers and may have weak or well-known passwords
They cannot be renamed
They prevent software installation
Which account is identified as the main Windows account with full control over the system?
Guest
Administrator
Root
User
Which account is the main Linux account with complete system access and is commonly targeted during hardening steps?
Guest
Administrator
Root
Operator
Which practice best describes a configuration baseline in system hardening?
A fixed, unchangeable image used for all systems regardless of role
A documented, approved starting set of settings that systems should conform to
A temporary configuration used only during testing
A backup of user data for disaster recovery
What is the primary benefit of automated configuration management tools when enforcing baselines?
They eliminate the need for human administrators entirely
They continuously apply and verify settings at scale to maintain compliance
They improve hardware performance by optimizing CPU usage
They encrypt all network traffic by default
Why should default accounts like Administrator, Guest, or root be deactivated or restricted?
They consume excessive storage space
They are widely known and commonly targeted by attackers
They prevent software updates from installing
They automatically expire after 30 days
Which action aligns with securing privileged access under a baseline policy?
Allow direct root or Administrator login over SSH/RDP for efficiency
Use shared credentials for all admins to simplify auditing
Require admins to log in with standard accounts and elevate privileges when needed
Disable logging to reduce noise
An organization wants every new server to start with the same hardened state, and drift from that state must be detected and corrected automatically. Which solution best fits this goal?
Manual checklists executed quarterly
Automated configuration management tied to an approved baseline
Relying on vendor default images only
Ad-hoc scripts run by each team as needed
Which is the most appropriate handling of a built-in Guest account on production systems?
Leave it enabled but rename it
Disable or remove it and deny interactive logon
Assign it to all contractors for temporary access
Require multi-factor authentication on it while keeping it enabled
What is the relationship between configuration baselines and auditing?
Baselines replace the need for audits
Auditing compares current configurations against the baseline to identify drift
Auditing is only concerned with user activities, not configurations
Baselines are created after an audit and never updated
Which statement best distinguishes a baseline from a snapshot?
A snapshot is an approved standard; a baseline is a point-in-time backup
A baseline defines desired configuration state; a snapshot captures current state at a moment in time
They are the same concept with different names
A baseline is only for networking gear; a snapshot is only for servers
Which statement best defines security patching in system hardening?
Replacing all software with new versions regardless of risk
Updating software or systems to fix weaknesses that attackers could exploit
Disabling unused services to reduce the attack surface
Encrypting all data at rest using full-disk encryption
Why do many organizations first deploy patches in a test environment?
To speed up installation across production systems
To ensure updates don’t cause problems before reaching working systems
To avoid using a centralized patching system
To allow end users to approve updates
What is the primary reason cipher suite deprecations occur?
Newer hardware requires different port numbers
Older suites are found to have weaknesses over time
Operating systems stop supporting encryption
Browsers cannot handle large keys
Which organization provides guidance recommending current cipher suites and removal of outdated ones for U.S. government agencies?
FCC
NIST
NSA
DHS
Which pair correctly lists common suites used to secure web traffic?
IPsec and SSH
TLS and SSL
SCP and SFTP
HTTPS and FTP
A security engineer wants to eliminate the use of Telnet for administrative access. Which secure alternative should be required?
SSH
HTTP
FTP
RDP
Which action best addresses the problem of unencrypted HTTP connections on a network?
Enable Telnet for faster logins
Limit HTTP and require HTTPS
Replace TLS with SSL
Use FTP for file transfers
To encrypt traffic for legacy protocols that lack built-in encryption, which technology can be configured to cover all network protocols?
RDP
IPsec
SCP
FTPS
What is the primary purpose of security patching?
To add new hardware features
To fix vulnerabilities and improve system security
To increase user interface customization
To reduce network bandwidth usage
Which type of patch is typically an urgent, targeted fix released outside the regular update cycle to address a specific critical issue?
Rollup
Hotfix
Signature update
Service pack
A web application firewall (WAF) rule is deployed to block an exploit until the developer can release code changes. What kind of patching approach is this?
Hotfix
Virtual patch
Rollup
Driver update
Signature updates most directly help with which capability?
Detecting known threats by pattern matching
Restoring corrupted files from backup
Upgrading operating system kernels
Enforcing password rotation policies
Which statement best describes a rollup?
A cumulative package bundling multiple patches into a single update
A test environment used before deployment
A tool that creates digital signatures for binaries
A method for reverting to a previous software version
You need to apply a critical security fix with minimal downtime to a production server. Which option best fits this requirement?
Schedule a quarterly rollup
Wait for the next signature update
Apply a hotfix
Deploy a full OS upgrade
Which is a best practice when applying security patches?
Patch directly on production without testing
Maintain an inventory and test patches in a staging environment before deployment
Disable logging to speed up patching
Only patch systems exposed to the internet
An organization uses a WAF to block a zero-day exploit while waiting for the vendor’s official fix. What is the main risk if they rely on this approach long term?
Virtual patches may not cover all attack vectors and can be bypassed
Hotfixes always require system reboots
Rollups cannot be uninstalled
Signature updates will delete legitimate traffic
