Free Managing-Cloud-Security Practice Test Questions and Answers (2026)

Last Update Check

View Mode
Q: 1
Which device is used to create and manage encryption keys used for data transmission in a cloud- based environment?
Options
Q: 2
An organization needs to provide space where security administrators can centrally monitor network traffic and events and respond to threats or outages. What should the organization create?
Options
Q: 3
An organization negotiates a new contract with a cloud provider and wants to ensure that its critical business data is protected if the cloud provider goes out of business. For this reason, the organization wants the cloud provider to store a copy of the organization's data with a neutral third party, which would release the data in case the provider is unable to meet its obligations. Which type of provision should be included in the contract to ensure this?
Options
Q: 4
Which phase of the cloud data life cycle involves the process of crypto-shredding?
Options
Q: 5
Which data destruction technique involves encrypting the data, followed by encrypting the resulting keys with a different engine, and then destroying the keys resulting from the second encryption round?
Options
Q: 6
Which release management term describes the process from code implementation to code review and approval to automated testing and then to production deployment?
Options
Q: 7
Which category of cloud service provides on-demand, self-service access to basic building blocks, such as virtualized servers, block storage, and networking capacity, that can be used to create custom IT solutions?
Options
Q: 8
A group of DevOps engineers adopted the network-as-code methodology to manage network infrastructure. During a code release, the engineers find a bug that is causing issues on a production site. Which safeguard will allow the engineers to restore functionality to the production site?
Options
Q: 9
An organization experienced an unplanned event. As a result, the customers using the web application face a loss of service. What does the incident generated in this situation seek to resolve?
Options
Q: 10
An organization wants to ensure that all entities trust any certificate generated internally in the organization. What should be used to generate these certificates?
Options
Q: 11
What is the process of identifying and procuring stored data as evidence for legal purposes?
Options
Q: 12
An organization creates a plan for long-term cloud storage of its backup dat a. What should the organization address to avoid losing access to its data?
Options
Q: 13
Which of the following is an iterative software development methodology that focuses on achieving customer satisfaction by delivering the software early in the process and welcoming changing requirements from the customer, even late in the process?
Options
Q: 14
A customer requests that a cloud provider physically destroys any drives storing their personal dat a. What must the provider do with the drives?
Options
Q: 15
A cloud provider that processes third-party credit card payments is unable to encrypt its customers' cardholder data because of constraints on a legacy payment processing system. What should it implement to maintain Payment Card Industry Data Security Standard (PCI DSS) compliance?
Options
Question 1 of 20

What's covered in this practice questions set

4: Cloud Governance, Risk, and Compliance, · 7 questions

📖 About this Domain

This domain covers the framework for directing and controlling cloud computing within an organization. It focuses on managing cloud-specific risks and ensuring adherence to legal, regulatory, and contractual requirements.

🎓 What You Will Learn

  • You will learn to apply governance frameworks like COBIT and ITIL to cloud environments for structured management.
  • You will learn to execute risk management processes, including risk identification, assessment, and mitigation for cloud assets.
  • You will learn to navigate the legal and compliance landscape, including data sovereignty, eDiscovery, and industry standards like PCI DSS and HIPAA.
  • You will learn the methodologies for auditing cloud environments and implementing continuous compliance monitoring.

🛠️ Skills You Will Build

  • You will build the skill to author cloud governance policies that align with enterprise security architecture.
  • You will build the skill to perform risk assessments on cloud service providers and specific cloud deployments.
  • You will build the skill to design compliance strategies that address the shared responsibility model.
  • You will build the skill to leverage cloud-native tools for automating GRC reporting and audit evidence collection.

💡 Top Tips to Prepare

  • Master the key differences between compliance frameworks like ISO 27001, SOC 2, and FedRAMP.
  • Deeply understand the shared responsibility model for IaaS, PaaS, and SaaS to correctly assign GRC tasks.
  • Practice applying risk assessment methodologies to hypothetical cloud migration and deployment scenarios.
  • Focus on the legal concepts of data residency and data sovereignty and their impact on cloud architecture.

1: Cloud Security Operations, · 3 questions

📖 About this Domain

This domain focuses on the day-to-day activities required to secure cloud environments. It covers the implementation of security controls, continuous monitoring, and incident management processes specific to cloud infrastructure.

🎓 What You Will Learn

  • You will learn to implement and manage security for cloud infrastructure, including compute, network, and storage resources.
  • You will learn to operate security controls, such as Security Information and Event Management (SIEM) and vulnerability management tools.
  • You will learn the processes for managing security incidents, including detection, response, and recovery in the cloud.
  • You will learn to conduct digital forensics and e-discovery within different cloud service models like IaaS, PaaS, and SaaS.

🛠️ Skills You Will Build

  • You will build skills in configuring and managing cloud-native security tools for continuous monitoring and logging.
  • You will develop the ability to execute incident response playbooks tailored for cloud-specific threats and architectures.
  • You will gain proficiency in cloud forensics, including data acquisition and evidence handling in a multi-tenant environment.
  • You will build skills in automating security operations using Security Orchestration, Automation, and Response (SOAR) principles.

💡 Top Tips to Prepare

  • Focus on the unique challenges of logging and monitoring in a distributed cloud environment, including ephemeral resources.
  • Memorize the incident response lifecycle (e.g., NIST SP 800-61) and how each phase applies to IaaS, PaaS, and SaaS.
  • Understand the legal and jurisdictional complexities of e-discovery and data acquisition across different geographic regions.
  • Practice with scenarios involving misconfigurations, API abuse, and compromised credentials, as these are common cloud operational issues.

2: Cloud Data Security, · 2 questions

📖 About this Domain

This domain focuses on the principles and technologies for securing data within cloud computing environments. It covers the entire data security lifecycle, from creation to destruction, emphasizing controls for data at rest, in transit, and in use.

🎓 What You Will Learn

  • Implement data discovery, classification, and labeling schemes to manage sensitive information across cloud platforms.
  • Apply encryption and key management strategies using services like KMS for data at rest and TLS for data in transit.
  • Configure Data Loss Prevention (DLP) policies and tools to detect and prevent unauthorized data exfiltration.
  • Manage data retention, deletion, and archival procedures to comply with regulatory and organizational requirements.

🛠️ Skills You Will Build

  • Architecting secure data storage solutions using object storage, block storage, and database services.
  • Managing cryptographic keys and secrets using cloud-native key management services.
  • Implementing data masking, tokenization, and anonymization techniques to protect personally identifiable information (PII).
  • Auditing data access and enforcing granular permissions using Identity and Access Management (IAM) policies.

💡 Top Tips to Prepare

  • Master the shared responsibility model as it applies specifically to data protection and encryption.
  • Practice configuring storage bucket policies, access control lists (ACLs), and encryption settings in a hands-on lab.
  • Understand the differences between server-side encryption (SSE) and client-side encryption and their use cases.
  • Memorize the data security lifecycle stages and the appropriate controls for each phase.

5: Cloud Security Fundamentals, · 1 questions

📖 About this Domain

This domain introduces the core concepts of cloud computing, security principles, and reference architectures. It covers cloud service models like IaaS, PaaS, and SaaS, and deployment models such as public, private, and hybrid clouds.

🎓 What You Will Learn

  • You will learn the essential characteristics of cloud computing as defined by NIST, including on-demand self-service and resource pooling.
  • You will differentiate between Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS) from a security perspective.
  • You will understand the division of security obligations in the shared responsibility model for each cloud service model.
  • You will explore foundational cloud security principles, including defense-in-depth and the principle of least privilege in a cloud context.

🛠️ Skills You Will Build

  • You will gain the ability to articulate the security implications of migrating workloads to different cloud service models.
  • You will develop the skill to apply the shared responsibility model to determine security ownership for cloud assets.
  • You will learn to identify inherent risks and benefits associated with various cloud deployment models.
  • You will build the competency to map traditional security controls to cloud-native security services and configurations.

💡 Top Tips to Prepare

  • Memorize the shared responsibility model for IaaS, PaaS, and SaaS, as it is a critical and frequently tested concept.
  • Focus on the NIST definitions for the five essential characteristics, three service models, and four deployment models.
  • Create comparison charts to clearly distinguish the management and security differences between IaaS, PaaS, and SaaS.
  • Understand the security challenges unique to the cloud, such as insecure APIs, misconfigurations, and multi-tenancy risks.

Premium Access Includes

  • Quiz Simulator
  • Exam Mode
  • Progress Tracking
  • Question Saving
  • Flash Cards
  • Drag & Drops
  • 3 Months Access
  • PDF Downloads
Get Premium Access
Scroll to Top