WorksheetsCloud Computing Worksheet
Total questions: 149
Worksheet time: 1hrs 15mins
What is cloud computing?
Storing data only on personal devices
Delivering computing services over the internet
Using only local servers
Running software without internet
Which cloud service provides virtual machines?
SaaS
PaaS
IaaS
DaaS
Which company is known as the first major cloud provider?
Microsoft
Amazon
IBM
Which cloud model shares infrastructure among multiple users?
Private
Hybrid
Public
Community
Pay-as-you-go pricing means:
Fixed monthly cost
Free services
Pay only for used resources
Unlimited usage
Which is NOT a cloud characteristic?
On-demand self-service
Elasticity
Measured service
Manual provisioning
Elasticity in cloud computing refers to:
Data encryption
Resource expansion and shrinkage
User authentication
Network isolation
Which deployment model combines public and private clouds?
Public
Private
Hybrid
Multi-cloud
IaaS users are responsible for:
Physical security
Hardware only
Operating systems and applications
Nothing
Which is an example of SaaS?
AWS EC2
Google App Engine
Gmail
Azure VM
PaaS mainly targets:
End users
System admins
Developers
Hackers
Which cloud model offers highest control?
Public
Private
Hybrid
Multi-cloud
A hypervisor is responsible for:
Data encryption
User authentication
Managing virtual machines
Network routing
Which hypervisor runs directly on hardware?
Hosted
Type II
Bare-metal
Type III
VMware ESXi is an example of:
Hosted hypervisor
Bare-metal hypervisor
Container engine
Application VM
VirtualBox is classified as:
Type I hypervisor
Type II hypervisor
Cloud platform
Container runtime
Which is a benefit of virtualization?
Increased hardware usage
Wasted resources
Isolation between VMs
Higher costs
VM isolation helps to:
Increase speed
Prevent malware spread
Delete data
Reduce backups
Which component acts as the brain of cloud architecture?
Front-end
Network layer
Cloud management software
Storage layer
The front-end of cloud architecture includes:
Hypervisors
Databases
Web browsers
Storage systems
Which provider launched in 2006?
Azure
AWS
GCP
Oracle Cloud
BigQuery belongs to:
AWS
Azure
GCP
IBM Cloud
Which cloud provider focuses on enterprise databases?
Oracle
Amazon
Microsoft
Virtualization allows multiple OS to run on:
Multiple servers
One physical machine
Cloud only
Containers only
The host machine provides:
Virtual disks
Hardware resources
Applications only
Network policies
Which file acts as a VM hard drive?
.exe
.iso
.vmdk
.log
Server virtualization is mainly used to:
Run desktops
Run mobile apps
Run multiple servers on one machine
Run containers only
Docker is an example of:
Server virtualization
Desktop virtualization
OS virtualization
Network virtualization
Which virtualization type pools storage devices?
Network
Storage
Application
Desktop
The VM lifecycle starts with:
Boot
Creation
Running
Migration
Which VM state saves memory without reboot?
Stop
Delete
Pause
Boot
Live migration means:
VM shutdown before move
Moving VM while running
Data deletion
VM cloning
VM sprawl refers to:
VM deletion
Uncontrolled VM growth
Hypervisor crash
Network failure
VM escape is when:
VM shuts down
VM accesses host or other VMs
Data loss occurs
Backup fails
The CIA triad stands for:
Control, Integrity, Access
Confidentiality, Integrity, Availability
Cloud, Internet, Access
Compute, Infrastructure, API
Data encryption protects data:
Only at rest
Only in transit
At rest and in transit
Only backups
MFA adds security by:
Removing passwords
Using single login
Multiple verification methods
Blocking users
Shared responsibility means:
Provider handles everything
User handles everything
Both share security roles
No one is responsible
In IaaS, customer is responsible for:
Physical servers
Virtualization layer
OS and applications
Data center security
Data breach means:
Data deletion
Unauthorized data access
Data backup
Data migration
Common cause of data breach is:
Strong IAM
MFA enabled
Misconfigured storage
Encryption
Data loss differs from breach because data is:
Encrypted
Stolen
Permanently unavailable
Backed up
Account hijacking often uses:
Firewalls
Phishing
MFA
Logs
Insecure APIs may cause:
Better performance
Unauthorized access
Lower cost
Data compression
DoS attacks originate from:
Many sources
Single source
Cloud provider
End users
DDoS attacks use:
One computer
Botnets
Firewalls
Hypervisors
Insider threats come from:
External hackers
Employees or partners
Firewalls only
Cloud providers
Misconfiguration often happens due to:
Too much security
Rapid deployment
Strong policies
Encryption
Malware injection targets:
Only hardware
Cloud apps and images
Passwords only
Firewalls
Which security layer protects traffic between VMs?
Host OS
Hypervisor
Virtual Network
Physical switch
Hypervisor attacks target:
Applications only
Guest OS
Hypervisor control layer
Network cables
VM sprawl mainly causes:
Better performance
Higher costs and weak security
Less storage usage
Faster backups
Resource contention attacks affect:
Only storage
Only network
CPU and memory sharing
Encryption keys
Hardening the hypervisor includes:
Disabling logs
Using default passwords
Regular patching
Sharing admin access
Snapshots are mainly used for:
Encryption
Backup and recovery
Load balancing
User authentication
Old snapshots are risky because they may cause:
Better performance
Data exposure
Faster migration
Higher availability
Cloud security focuses on protecting:
Only data
Only hardware
Data, applications, and infrastructure
Only users
Which is NOT a cloud security best practice?
Data encryption
Strong IAM
Leaving default settings
Multi-factor authentication
Multi-tenancy risk refers to:
Single user systems
Shared infrastructure among users
Offline storage
Local databases
Expanded attack surface in cloud comes from:
APIs and consoles
Physical locks
Local disks
Offline servers
The shared responsibility model differs based on:
Cloud color
Service model
User location
Internet speed
In SaaS, user responsibility is mainly:
Hardware security
App updates
User access and data usage
Hypervisor management
Which threat involves stolen credentials?
Data loss
Account hijacking
Malware injection
Worms
Weak IAM policies may lead to:
Lower costs
Privilege escalation
Better auditing
Faster deployment
Data breach prevention includes:
Disabling logs
Least privilege access
Public storage
Missing MFA
Versioning helps prevent:
Data breach
Data loss
Account hijacking
DoS attacks
Phishing is commonly used in:
DoS attacks
Account hijacking
Encryption
Migration
Insecure APIs are dangerous because they:
Improve speed
Expose services and data
Reduce costs
Block users
Rate limiting helps prevent:
Data loss
API abuse
Disk failure
Insider threats
DoS attacks mainly affect:
Confidentiality
Integrity
Availability
Authentication
DDoS attacks are harder to stop because they are:
Encrypted
Single source
Distributed
Malware-based
Auto-scaling during DDoS may cause:
Lower cost
Higher cloud bills
Data encryption
Faster recovery
Insider threat can be:
Only malicious
Only accidental
Malicious or negligent
Only external
Least privilege principle means:
Full access by default
Access only what is needed
No access at all
Shared credentials
Misconfigured storage often results in:
Public data exposure
Better redundancy
Faster access
Stronger encryption
Default cloud settings are risky because they are:
Always secure
Generic and open
Encrypted
Private
IaC helps reduce misconfiguration by:
Manual setup
Automated consistent configs
Disabling logs
Removing IAM
Malware injection often exploits:
Strong CI/CD
Insecure pipelines
Encryption
MFA
Compromised container images may contain:
Updates
Malware patches
Backdoors
Firewalls
Supply-chain attacks target:
Physical servers
Dependencies and libraries
Hypervisors only
VM snapshots
Cryptomining malware abuses:
Storage only
Compute resources
Network cables
Encryption keys
Cryptojacking is often detected by:
Low CPU usage
High unexpected bills
Strong IAM
Faster apps
Ransomware mainly impacts:
Availability of data
Network speed
API calls
VM migration
Cloud ransomware often spreads via:
Shared storage
Local disks
Offline backups
Physical access
Worms are dangerous in cloud because they:
Need user interaction
Self-propagate quickly
Require admin login
Are encrypted
Cloud malware detection relies on:
Physical inspection
Log analysis and behavior monitoring
USB scans
Offline tools
SIEM tools help by:
Blocking users
Centralizing logs and alerts
Deleting data
Creating VMs
Defense-in-depth means:
One security layer
Multiple layered controls
No monitoring
Only encryption
Sandboxing is used to:
Run production apps
Test suspicious code safely
Delete malware automatically
Encrypt disks
Access control defines:
Who accesses what
How fast apps run
Where data is stored
VM size
DAC allows access decisions by:
Security authority
Resource owner
Hypervisor
Cloud provider
MAC is commonly used in:
Startups
E-commerce
Government systems
Gaming apps
RBAC assigns permissions based on:
User attributes
User roles
Network location
Time only
ABAC decisions depend on:
Single factor
Multiple attributes
Hardcoded rules
Manual approval
IAM authentication verifies:
User permissions
User identity
Data encryption
VM state
IAM authorization determines:
Who you are
What you can do
Where data is stored
When VM stops
Orphaned accounts are dangerous because they:
Improve access
Remain active without owners
Encrypt data
Reduce costs
MFA significantly reduces risk of:
Account hijacking
Data replication
VM migration
Log collection
Centralized IAM helps in:
Reducing visibility
Managing access consistently
Increasing misconfigurations
Removing compliance
Cloud forensics focuses on:
Physical devices
Investigating cloud incidents
Network installation
App development
Which is a key challenge in cloud forensics?
Single tenancy
Lack of physical access
Local storage
Offline data
Multi-tenancy complicates forensics because:
Only one user exists
Multiple customers share infrastructure
Data is encrypted
Logs are deleted
Distributed data means:
Data stored in one server
Data spread across regions
Data stored offline
Data deleted quickly
Which is a primary evidence source in cloud forensics?
USB drives
VM snapshots
Physical disks
BIOS logs
Cloud logs provide:
Encryption keys
User activity timelines
Physical access history
Hardware temperature
API logs record:
CPU usage
API calls and actions
User passwords
File encryption
Authentication logs show:
Data backups
Login attempts and MFA events
VM deletion
Network speed
Network logs help investigate:
User roles
Traffic flows and attacks
File permissions
App versions
VM snapshots capture:
Only RAM
Complete VM state
Network cables
User credentials only
Memory dumps are valuable because they contain:
Stored backups
Volatile runtime data
Physical disks
Encrypted archives
Which evidence may reveal encryption keys?
Log files
Memory dumps
VM templates
Backups
Chain of custody ensures:
Faster investigation
Evidence integrity and authenticity
Higher performance
Lower cost
Cloud chain of custody is harder due to:
Too many tools
Provider-controlled infrastructure
Local servers
Offline access
Timestamp inconsistency occurs due to:
Single region systems
Multiple regions and services
Offline storage
Manual backups
Evidence contamination risk increases because of:
Encryption
MFA
Shared infrastructure
Firewalls
Forensic investigators rely on CSP for:
Password cracking
Evidence access and collection
App development
Hardware repair
Which helps maintain forensic integrity?
Hashing evidence
Deleting logs
Sharing accounts
Public storage
Audit trails are important for:
Performance tuning
Tracking user actions
UI design
App testing
Which cloud feature complicates evidence location?
Elasticity
Versioning
Auto-scaling
Centralization
Compliance ensures:
Faster systems
Legal and regulatory adherence
Lower latency
Higher bandwidth
GDPR mainly focuses on:
Financial audits
Data privacy and protection
Network security
App development
HIPAA regulates:
E-commerce data
Healthcare information
Payment cards
Social media
PCI DSS applies to:
Healthcare
Cloud providers only
Payment card data
Education systems
ISO/IEC 27001 addresses:
Network speed
Information security management
App coding
Virtual machines only
Data residency violations occur when:
Data is encrypted
Data stored in unauthorized regions
Data is backed up
Data is compressed
Non-compliance may result in:
Lower costs
Heavy fines and penalties
Better reputation
Faster deployment
Shared responsibility confusion can cause:
Better security
Security gaps
More automation
Higher availability
Which tool helps manage compliance?
AWS Artifact
Text editor
Docker Hub
FTP server
Encryption helps compliance by:
Hiding users
Protecting sensitive data
Deleting logs
Reducing access
Cloud malware differs by:
Being offline
Exploiting cloud features
Using USB drives
Needing physical access
Ransomware encrypts:
Network traffic
Data for ransom
Hardware
APIs
Crypto-mining malware abuses:
GPUs and CPUs
Storage only
Log files
Backups
Cloud worms spread via:
Physical cables
APIs and automation
Manual installation
Offline disks
Auto-scaling can worsen malware impact by:
Limiting spread
Providing more resources
Blocking traffic
Encrypting data
Unexpected billing spikes may indicate:
Normal usage
Cryptojacking
Strong security
Backups running
Runtime monitoring helps detect:
Design flaws
Abnormal behavior
Password length
File formats
SBOMs help by:
Listing software components
Hiding dependencies
Deleting malware
Encrypting disks
Image scanning is used to detect:
Network errors
Malicious components
UI bugs
User roles
Secure CI/CD pipelines reduce risk of:
Faster builds
Malware injection
Strong encryption
Log management
Least privilege reduces:
Usability
Attack impact
Compliance
Costs only
Temporary credentials help by:
Never expiring
Limiting exposure time
Sharing access
Removing MFA
SSO improves security by:
Multiple passwords
Centralized authentication
Removing logging
Public access
Zero Trust assumes:
Internal users are trusted
No user is trusted by default
Cloud is unsafe
Encryption is enough
UEBA helps detect:
Hardware failures
User behavior anomalies
Data backups
Virtual disks
Log retention supports:
Forensics and compliance
Performance tuning only
App updates
UI design
Data classification helps identify:
Storage size
Sensitivity levels
Network routes
VM speed
Compliance audits ensure:
Policy adherence
Network speed
Lower cost
User convenience
Cloud compliance tools provide:
Manual reports
Continuous monitoring
Game engines
VM snapshots only
Failure to meet regulations may cause:
More customers
Legal action
Lower security
Faster growth
