wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Unit V

Total questions: 20

Worksheet time: 10mins

Name
Class
Date
1.

During proactive monitoring, a security tool raises an alert for repeated failed login attempts across multiple cloud VMs. What is the MOST appropriate next step?

a)

Disable all user accounts immediately

b)

Correlate events and trigger automated incident response

c)

Ignore the alert as false positive

d)

Reboot the affected VMs

2.

If an incident response plan fails to contain lateral movement after detection of malware, which proactive control was MOST likely insufficient?

a)

Network segmentation and monitoring

b)

Single-factor authentication

c)

Storage encryption

d)

RBAC hierarchy

3.

A cloud system generates logs for all administrative actions. During analysis, it is observed that a user accessed resources outside their role. What is the primary failure?

a)

Authentication bypass

b)

Broken chain of trust

c)

Data encryption failure

d)

Authorization inconsistency

4.

Multi-factor authentication (MFA) is enabled, but attackers still gain access using stolen tokens. Which monitoring capability could have mitigated the attack?

a)

SSL certificate validation

b)

Role hierarchy correction

c)

Event correlation for anomalous geolocation

d)

QoS enforcement

5.

A cloud firewall logs indicate high-volume outbound traffic from an internal VM to unknown IP addresses. Which type of alert is MOST appropriate?

a)

Denial-of-service detection

b)

Data exfiltration alert

c)

Privilege escalation notification

d)

RBAC violation

6.

An administrator account is used to access sensitive data outside normal business hours. Which combination of monitoring tools would BEST detect this?

a)

RBAC enforcement and QoS metrics

b)

Event logs correlation and anomaly detection

c)

TLS certificate validation and firewall logging

d)

Cloud bursting metrics and geo-tagging

7.

Privilege abuse in cloud systems often occurs due to inherited permissions. Which mitigation strategy is most effective?

a)

Principle of least privilege (POLP)

b)

Cloud bursting

c)

Role hierarchy flattening

d)

Geo-fencing

8.

A SIEM system raises multiple alerts simultaneously for different anomalies. The security team fails to prioritize, leading to delayed response. Which SIEM feature was underutilized?

a)

Single-factor authentication

b)

RBAC enforcement

c)

Event correlation and severity scoring

d)

Storage encryption

9.

Alert fatigue can reduce incident response efficiency. Which design approach reduces false positives?

a)

Context-aware alerting and correlation

b)

Manual log review only

c)

Manual log review only

d)

Removing MFA requirements

10.

During an audit, it is found that log records are incomplete for critical cloud actions. Which is the PRIMARY risk?

a)

Authentication failure

b)

OS-level vulnerabilities

c)

Non-compliance and failed forensic analysis

d)

QoS degradation

11.

Automated reporting ensures timely compliance. What is a critical consideration when designing report generation?

a)

Flat RBAC assignment

b)

Tamper-proof log integrity and timestamping

c)

Encryption of storage only

d)

Role explosion prevention

12.

A compromised OS image still passes integrity verification. Which tamper-proofing measure is MOST relevant?

a)

Blockchain-based logging or signed logs

b)

Encryption of log data only

c)

Role-based access control

d)

QoS monitoring

13.

If security monitoring introduces latency in a cloud application, which QoS metric is MOST affected?

a)

Response time and availability

b)

Role hierarchy accuracy

c)

Identity federation

d)

Log integrity

14.

Integrating security controls should maintain QoS to avoid:

a)

OS integrity issues

b)

RBAC enforcement failures

c)

Denial-of-service impact on legitimate users

d)

Token misuse

15.

A cloud admin creates accounts without enforcing MFA. Which risk increases the MOST?

a)

Unauthorized access to critical resources

b)

Data integrity compromise

c)

Tamper-proof log violation

d)

QoS degradation

16.

If identity federation is misconfigured in a multi-cloud environment, which failure occurs MOST frequently?

a)

Authorization inconsistency

b)

OS-level compromise

c)

QoS degradation

d)

Audit log tampering

17.

SIEM correlates events across multiple sources. Which scenario BEST demonstrates its effectiveness?

a)

Cloud bursting automation

b)

Enforcing RBAC in storage access

c)

Encrypting audit logs only

d)

Detecting coordinated attacks spanning network, applications, and cloud services

18.

An external contractor is provisioned cloud access using federated SSO without validating roles. Which risk arises?

a)

Authorization inconsistency

b)

OS-level compromise

c)

Tamper-proof logging failure

d)

QoS degradation

19.

During a cloud attack simulation, the security team notices that malware spreads only to systems with open SSH ports. Which proactive control could have limited this lateral movement?

a)

Encrypting backup storage

b)

Role-based access control

c)

Goe location based policy enforcement

d)

Network segmentation with restricted port access

20.

An employee successfully accesses sensitive data at unusual times without triggering alerts. What monitoring gap MOST likely caused this?

a)

Absence of RBAC

b)

Missing encryption on storage

c)

Lack of user behavior analytics (UBA)

d)

Overloaded QoS system