Q1
Easy
10 pts
Cloud Security (AWS & Azure)
Defending the cloud: shared responsibility, IAM, S3/storage, logging and misconfigurations.
Q2
Easy
10 pts
A very common AWS misconfiguration exposing data publicly is:
Q3
Medium
15 pts
The AWS service managing users, roles and permissions is ____ (acronym).
Q4
Medium
15 pts
Which AWS service records API activity for auditing?
Q5
Medium
15 pts
Microsoft Azure's cloud identity service is:
Q6
Hard
20 pts
Using short-lived assumable roles instead of long-lived credentials avoids leaking permanent access ____ .
Q7
Medium
15 pts
The AWS root account should be:
Q8
Hard
20 pts
IMDSv2 (Instance Metadata Service v2) mitigates:
Q9
Medium
15 pts
AWS KMS is used to:
Q10
Medium
15 pts
AWS GuardDuty provides:
Q11
Medium
15 pts
An over-privileged IAM policy (e.g. `*:*`) is risky because:
Q12
Medium
15 pts
Security Groups in AWS act as:
Q13
Hard
20 pts
Network ACLs (NACLs) differ from security groups by being:
Q14
Medium
15 pts
'Block Public Access' for S3 should generally be:
Q15
Medium
15 pts
Encrypting EBS volumes and S3 objects addresses:
Q16
Hard
20 pts
AWS Config is used to:
Q17
Medium
15 pts
Azure NSGs (Network Security Groups) control:
Q18
Medium
15 pts
Azure Key Vault stores:
Q19
Medium
15 pts
Microsoft Defender for Cloud provides:
Q20
Hard
20 pts
CSPM (Cloud Security Posture Management) tools primarily:
Q21
Hard
20 pts
CWPP focuses on protecting:
Q22
Hard
20 pts
A CASB sits between users and cloud services to:
Q23
Medium
15 pts
AWS Shield helps defend against:
Q24
Easy
10 pts
Enabling MFA on privileged cloud accounts primarily prevents:
Q25
Medium
15 pts
Key rotation in KMS/Key Vault is important to:
Q26
Hard
20 pts
A public snapshot/AMI is risky because it may:
Q27
Hard
20 pts
VPC Flow Logs capture:
Q28
Medium
15 pts
An IAM 'role' differs from a 'user' in that a role:
Q29
Medium
15 pts
Least privilege in the cloud is best achieved by:
Q30
Easy
10 pts
Encrypting data in transit in the cloud uses:
Q31
Hard
20 pts
A 'confused deputy' cross-account access issue is mitigated by:
Q32
Medium
15 pts
EKS/AKS/GKE are managed:
Q33
Medium
15 pts
Storing secrets in environment variables baked into an image is:
Q34
Medium
15 pts
The AWS Well-Architected 'Security' pillar emphasizes:
Q35
Easy
10 pts
Cloud pentesting requires:
Q36
Medium
15 pts
Disabling unused regions/services reduces:
Q37
Hard
20 pts
Centralized logging across accounts (e.g. to a security account) helps:
Q38
Medium
15 pts
A 'least-privilege' S3 bucket policy should:
Q39
Hard
20 pts
Conditional Access (Entra ID) enforces:
Q40
Medium
15 pts
Public access to a cloud database (e.g. open Elasticsearch/Mongo) usually results in:
Q41
Medium
15 pts
Tagging cloud resources supports security by:
Q42
Hard
20 pts
A guardrail like SCP (Service Control Policy) in AWS Organizations:
Q43
Medium
15 pts
Data residency requirements affect:
Q44
Medium
15 pts
Rotating and scoping cloud access keys reduces the impact of:
Q45
Medium
15 pts
Encrypting inter-service traffic within a VPC helps against:
Q46
Hard
20 pts
A misconfigured cloud IAM trust policy can allow:
Q47
Medium
15 pts
Security Hub / centralized findings help teams:
Q48
Easy
10 pts
The safest default for a new cloud resource's network exposure is:
Q49
Hard
20 pts
Immutable, versioned logging (e.g. S3 Object Lock) protects logs from:
Q50
Medium
15 pts