/50

Cybersecurity & Cloud Computing Exam

Instructions: You have 60 Minutes to complete the exam. Read each question carefully and select the best answer. Ensure you submit before the timer expires.

Begin when ready. Good luck!

Please enter the same email address you used during the class. This helps us verify your identity and record your quiz results correctly.

1 / 50

What is the primary purpose of the CSA STAR Registry?

2 / 50

Which function in the NIST Cybersecurity Framework (CSF) focuses on developing
safeguards to limit the impact of cybersecurity events?

3 / 50

Which factor most directly links the Cloud Controls Matrix (CCM) to international security
standards?

4 / 50

Which of the following is a best practice for Identity & Access Management (IAM)?

5 / 50

Which scenario BEST illustrates the cybersecurity threat posed by deepfake technology?

6 / 50

Which statement best describes the purpose of Organizational Context?

7 / 50

You want to detect the version of services running on open ports. Which Nmap option should you use?

8 / 50

In the CSA CCM, which domain focuses on controlling user identities, authentication, and access rights?

9 / 50

What is the PRIMARY purpose of network segmentation in security architecture?

10 / 50

Kali Linux is best described as:

11 / 50

Which option best fits Cybersecurity Supply Chain Risk Management?

12 / 50

What is the first phase of building a cloud security roadmap?

13 / 50

Which STAR level involves independent third-party auditing?

14 / 50

Which of the following is a recommended practice for Encryption & Key Management (EKM)?

15 / 50

Which cloud security challenge is Zero Trust designed to address?

16 / 50

Which of the following BEST explains why quantum computing represents a major
cybersecurity risk?

17 / 50

Which of the following aligns with Roles, Responsibilities, and Authorities?

18 / 50

Which organization created the Cloud Controls Matrix (CCM) framework for cloud security?

19 / 50

Which option best describes how DE.CM (Continuous Monitoring) and DE.AE
(Anomalies and Events) work together in a cybersecurity environment?

20 / 50

An employee accidentally uploads confidential client data to a publicly accessible cloud bucket. This
incident is BEST classified as:

21 / 50

When using OWASP ZAP in man‑in‑the‑middle proxy mode, what is the first step to intercept traffic?

22 / 50

Zero Trust Architecture
Modern cybersecurity models have shifted away from perimeter-based assumptions. Zero Trust
Architecture rejects the notion that users or devices within a network are inherently secure. Instead, it requires continuous validation of identity, device health, and permissions.
Which of the following statements BEST reflects the foundation of the Zero Trust security
philosophy?

23 / 50

What is the goal of the Risk Management Strategy category?

24 / 50

What is the primary purpose of RS.AN (Analysis) in incident response?

25 / 50

Which of the following BEST describes how cybercriminals leverage AI to enhance their attack
capabilities?

26 / 50

Which OWASP Top 10 risk refers to flaws that allow attackers to execute unauthorized code or commands?

27 / 50

After a ransomware attack on a payment service provider, IT restores clean servers
from offline backups and the security team validates that no malware remains. What
does this activity represent?

28 / 50

Which of the following is a short-term containment action in cloud incident response?

29 / 50

According to the CSA CCM structure, what is the PRIMARY role of the GRC domain?

30 / 50

Under NIST CSF, what is the primary purpose of the “Detect” function?

31 / 50

Which Nmap command is used to perform a simple TCP SYN scan?

32 / 50

Which incident response phase focuses on identifying lessons learned and improving future
security posture?

33 / 50

What is the primary goal of Vulnerability Assessment and Penetration Testing (VAPT)?

34 / 50

Which IR (Incident Response) stage focuses on identifying abnormal activity through alerts
and logs?

35 / 50

Which Kali Linux tool is most suitable for exploiting known vulnerabilities after scanning?

36 / 50

A developer stores passwords in plain text in the database. Which OWASP Top 10 risk does this represent?

37 / 50

What is the focus of Oversight within the NIST CSF?

38 / 50

During a penetration test, you discover a web application vulnerable to SQL injection. Which payload would best confirm the vulnerability?

39 / 50

An employee accidentally uploads confidential client data to a publicly accessible cloud bucket. The
incident is BEST classified as:

40 / 50

Which of the following best describes the primary purpose of AWS GuardDuty in this
scenario?

41 / 50

The Data Security & Information Lifecycle (DSI) domain ensures data is protected during which of the following stages?

42 / 50

Which scenario BEST demonstrates a failure of the Shared Responsibility Model in a cloud
environment?

43 / 50

OWASP ZAP is primarily used for:

44 / 50

Which security principle is MOST aligned with enforcing least privilege in a zero-trust
architecture?

45 / 50

Which combination of controls would MOST effectively reduce the risk of cloud misconfiguration
leading to data exposure?

46 / 50

Which of the following factors MOST contributes to the increased cybersecurity risk posed by
IoT devices?

47 / 50

Disabling compromised credentials immediately

48 / 50

In Secure SDLC, at what stage should security be integrated into the development process?

49 / 50

What does the Cloud Controls Matrix (CCM) primarily provide?

50 / 50

What is the main objective of the Respond (RS) function in a cybersecurity
framework?

Your score is

0%