NEW
Font size
WorksheetsUnit V
Total questions: 20
Worksheet time: 10mins
During proactive monitoring, a security tool raises an alert for repeated failed login attempts across multiple cloud VMs. What is the MOST appropriate next step?
Disable all user accounts immediately
Correlate events and trigger automated incident response
Ignore the alert as false positive
Reboot the affected VMs
If an incident response plan fails to contain lateral movement after detection of malware, which proactive control was MOST likely insufficient?
Network segmentation and monitoring
Single-factor authentication
Storage encryption
RBAC hierarchy
A cloud system generates logs for all administrative actions. During analysis, it is observed that a user accessed resources outside their role. What is the primary failure?
Authentication bypass
Broken chain of trust
Data encryption failure
Authorization inconsistency
Multi-factor authentication (MFA) is enabled, but attackers still gain access using stolen tokens. Which monitoring capability could have mitigated the attack?
SSL certificate validation
Role hierarchy correction
Event correlation for anomalous geolocation
QoS enforcement
A cloud firewall logs indicate high-volume outbound traffic from an internal VM to unknown IP addresses. Which type of alert is MOST appropriate?
Denial-of-service detection
Data exfiltration alert
Privilege escalation notification
RBAC violation
An administrator account is used to access sensitive data outside normal business hours. Which combination of monitoring tools would BEST detect this?
RBAC enforcement and QoS metrics
Event logs correlation and anomaly detection
TLS certificate validation and firewall logging
Cloud bursting metrics and geo-tagging
Privilege abuse in cloud systems often occurs due to inherited permissions. Which mitigation strategy is most effective?
Principle of least privilege (POLP)
Cloud bursting
Role hierarchy flattening
Geo-fencing
A SIEM system raises multiple alerts simultaneously for different anomalies. The security team fails to prioritize, leading to delayed response. Which SIEM feature was underutilized?
Single-factor authentication
RBAC enforcement
Event correlation and severity scoring
Storage encryption
Alert fatigue can reduce incident response efficiency. Which design approach reduces false positives?
Context-aware alerting and correlation
Manual log review only
Manual log review only
Removing MFA requirements
During an audit, it is found that log records are incomplete for critical cloud actions. Which is the PRIMARY risk?
Authentication failure
OS-level vulnerabilities
Non-compliance and failed forensic analysis
QoS degradation
Automated reporting ensures timely compliance. What is a critical consideration when designing report generation?
Flat RBAC assignment
Tamper-proof log integrity and timestamping
Encryption of storage only
Role explosion prevention
A compromised OS image still passes integrity verification. Which tamper-proofing measure is MOST relevant?
Blockchain-based logging or signed logs
Encryption of log data only
Role-based access control
QoS monitoring
If security monitoring introduces latency in a cloud application, which QoS metric is MOST affected?
Response time and availability
Role hierarchy accuracy
Identity federation
Log integrity
Integrating security controls should maintain QoS to avoid:
OS integrity issues
RBAC enforcement failures
Denial-of-service impact on legitimate users
Token misuse
A cloud admin creates accounts without enforcing MFA. Which risk increases the MOST?
Unauthorized access to critical resources
Data integrity compromise
Tamper-proof log violation
QoS degradation
If identity federation is misconfigured in a multi-cloud environment, which failure occurs MOST frequently?
Authorization inconsistency
OS-level compromise
QoS degradation
Audit log tampering
SIEM correlates events across multiple sources. Which scenario BEST demonstrates its effectiveness?
Cloud bursting automation
Enforcing RBAC in storage access
Encrypting audit logs only
Detecting coordinated attacks spanning network, applications, and cloud services
An external contractor is provisioned cloud access using federated SSO without validating roles. Which risk arises?
Authorization inconsistency
OS-level compromise
Tamper-proof logging failure
QoS degradation
During a cloud attack simulation, the security team notices that malware spreads only to systems with open SSH ports. Which proactive control could have limited this lateral movement?
Encrypting backup storage
Role-based access control
Goe location based policy enforcement
Network segmentation with restricted port access
An employee successfully accesses sensitive data at unusual times without triggering alerts. What monitoring gap MOST likely caused this?
Absence of RBAC
Missing encryption on storage
Lack of user behavior analytics (UBA)
Overloaded QoS system
