/50 Your exam session is now complete.If the timer reached zero, your answers have been automatically submitted. Thank you for participating. Cybersecurity & Cloud Computing Exam Instructions: You have 60 Minutes to complete the exam. Read each question carefully and select the best answer. Ensure you submit before the timer expires. Begin when ready. Good luck! Please enter the same email address you used during the class. This helps us verify your identity and record your quiz results correctly. 1 / 50 What is the primary purpose of the CSA STAR Registry? To rate cloud providers based on customer reviews To provide a public platform for cloud providers to disclose their security posture To sell cloud security tools To enforce penalties for insecure cloud vendors 2 / 50 Which function in the NIST Cybersecurity Framework (CSF) focuses on developing safeguards to limit the impact of cybersecurity events? Identify Protect Detect Respond 3 / 50 Which factor most directly links the Cloud Controls Matrix (CCM) to international security standards? Its division into 17 domains Its total of 197 objectives Its mapping to ISO 27001, NIST, and PCI-DSS Its update cycle every three years 4 / 50 Which of the following is a best practice for Identity & Access Management (IAM)? Granting all users administrator rights Using single‑factor authentication only Applying the Principle of Least Privilege (PoLP) Avoiding access reviews 5 / 50 Which scenario BEST illustrates the cybersecurity threat posed by deepfake technology? A hacker using malware to capture keystrokes on a workstation. An employee falling for a spoofed email due to misconfigured spam filters. A deepfake audio clip convincing a company’s finance officer to authorise a fraudulent funds transfer. Social media accounts being compromised due to weak passwords. 6 / 50 Which statement best describes the purpose of Organizational Context? It sets the company’s technical controls for access management It helps the organization understand its mission, stakeholders, and requirements that influence cybersecurity decisions It defines backup and recovery procedures It provides steps for handling insider threats 7 / 50 You want to detect the version of services running on open ports. Which Nmap option should you use? -sS -sV -O -Pn 8 / 50 In the CSA CCM, which domain focuses on controlling user identities, authentication, and access rights? DSI IAM EKM RBAC 9 / 50 What is the PRIMARY purpose of network segmentation in security architecture? Increase bandwidth Simplify patch management Limit the lateral movement of attackers Improve wireless coverage 10 / 50 Kali Linux is best described as: A general‑purpose operating system A penetration testing and security auditing distribution A cloud storage platform A firewall appliance 11 / 50 Which option best fits Cybersecurity Supply Chain Risk Management? Monitoring employee training completion Ensuring backups are tested quarterly Understanding and managing cybersecurity risks that come from suppliers and third parties Updating password policies every six months 12 / 50 What is the first phase of building a cloud security roadmap? Implement controls Monitor and audit Assess and baseline your current posture Select a cloud provider 13 / 50 Which STAR level involves independent third-party auditing? STAR Level 1 STAR Level 3 STAR Level 2 STAR Level 0 14 / 50 Which of the following is a recommended practice for Encryption & Key Management (EKM)? Store encryption keys alongside encrypted data Rotate keys regularly to reduce exposure Use the same key for all systems indefinitely Avoid hardware security modules (HSMs) 15 / 50 Which cloud security challenge is Zero Trust designed to address? Reducing cloud spending Increasing speed of deployment Always verifying access regardless of location Supporting multi-cloud billing 16 / 50 Which of the following BEST explains why quantum computing represents a major cybersecurity risk? Quantum computers automatically patch vulnerabilities in real-time. They can instantly clone any digital identity regardless of authentication controls. They may eventually break traditional encryption algorithms, exposing sensitive data. They allow attackers to bypass network segmentation without detection. 17 / 50 Which of the following aligns with Roles, Responsibilities, and Authorities? Ensuring hardware inventory is maintained Making sure leadership is accountable for cybersecurity risk and resources are properly allocated Protecting data during transmission Ensuring incident response plans are updated 18 / 50 Which organization created the Cloud Controls Matrix (CCM) framework for cloud security? ISO NIST Cloud Security Alliance (CSA) PCI DSS 19 / 50 Which option best describes how DE.CM (Continuous Monitoring) and DE.AE (Anomalies and Events) work together in a cybersecurity environment? DE.CM analyzes threats, while DE.AE collects real-time data from systems and networks. DE.CM and DE.AE both perform incident recovery and restoration. DE.CM handles user training, while DE.AE manages access control. DE.CM collects real-time monitoring data, and DE.AE interprets that data to detect and prioritize anomalies. 20 / 50 An employee accidentally uploads confidential client data to a publicly accessible cloud bucket. This incident is BEST classified as: Malicious insider threat Negligent insider risk External data breach Compromised insider account 21 / 50 When using OWASP ZAP in man‑in‑the‑middle proxy mode, what is the first step to intercept traffic? Configure browser to use ZAP proxy Run nmap -sV Enable HSTS bypass Launch Hydra brute force 22 / 50 Zero Trust Architecture Modern cybersecurity models have shifted away from perimeter-based assumptions. Zero Trust Architecture rejects the notion that users or devices within a network are inherently secure. Instead, it requires continuous validation of identity, device health, and permissions. Which of the following statements BEST reflects the foundation of the Zero Trust security philosophy? Users inside the network perimeter can be trusted, but external users must be verified continuously. Trust is granted based on previously successful logins to reduce authentication overhead. “Never trust, always verify”—every request must be authenticated, authorized, and assessed using real-time signals. All devices with valid certificates should be granted network-wide access. 23 / 50 What is the goal of the Risk Management Strategy category? To assign physical security guards to critical facilities To establish and communicate the organization’s priorities, constraints, and risk tolerance To perform routine vulnerability scanning To approve software before installation 24 / 50 What is the primary purpose of RS.AN (Analysis) in incident response? To analyze incidents to understand their cause, scope, and impact for informed decision-making and targeted remediation. To immediately restore all affected systems without investigation. To monitor network traffic for suspicious activity. To notify customers before understanding the incident details 25 / 50 Which of the following BEST describes how cybercriminals leverage AI to enhance their attack capabilities? Using AI-driven security tools to test their own defences before launching attacks. Automating vulnerability patching across compromised devices. Deploying AI-powered phishing campaigns that craft personalised messages and reduce breakout times. Conducting manual reconnaissance to identify weak points in organisational defences. 26 / 50 Which OWASP Top 10 risk refers to flaws that allow attackers to execute unauthorized code or commands? Broken Authentication Injection Security Misconfiguration Sensitive Data Exposure 27 / 50 After a ransomware attack on a payment service provider, IT restores clean servers from offline backups and the security team validates that no malware remains. What does this activity represent? Recovery actions to restore safe and secure operations Routine system maintenance System hardening for future upgrades Network performance optimization 28 / 50 Which of the following is a short-term containment action in cloud incident response? Patching all workloads Revising IAM policies Updating firewall rules Disabling compromised credentials immediately 29 / 50 According to the CSA CCM structure, what is the PRIMARY role of the GRC domain? Managing user identities and authentication Regulating encryption standards for cloud storage Defining organizational policies, assessing risks, and ensuring compliance Monitoring system uptime and availability 30 / 50 Under NIST CSF, what is the primary purpose of the “Detect” function? Prevent unauthorised access Develop contingency plans Discover anomalies and potential cybersecurity events Restore services after an incident 31 / 50 Which Nmap command is used to perform a simple TCP SYN scan? nmap -sP nmap -sS nmap -O nmap -A 32 / 50 Which incident response phase focuses on identifying lessons learned and improving future security posture? Detection & Analysis Containment Recovery Post-incident activities 33 / 50 What is the primary goal of Vulnerability Assessment and Penetration Testing (VAPT)? To permanently fix all vulnerabilities To identify and exploit weaknesses for security improvement To replace firewalls To monitor network traffic only 34 / 50 Which IR (Incident Response) stage focuses on identifying abnormal activity through alerts and logs? Containment Detection Eradication Recovery 35 / 50 Which Kali Linux tool is most suitable for exploiting known vulnerabilities after scanning? Metasploit Framework Wireshark John the Ripper Nikto 36 / 50 A developer stores passwords in plain text in the database. Which OWASP Top 10 risk does this represent? Broken Access Control Cryptographic Failures Security Misconfiguration Injection 37 / 50 What is the focus of Oversight within the NIST CSF? Tracking the organization’s network traffic Reviewing cybersecurity performance to adjust risk management strategy Managing identities and credentials Preventing unauthorized software installation 38 / 50 During a penetration test, you discover a web application vulnerable to SQL injection. Which payload would best confirm the vulnerability? OR 1=1-- alert(1) ../../etc/passwd nmap -sS target 39 / 50 An employee accidentally uploads confidential client data to a publicly accessible cloud bucket. The incident is BEST classified as: Malicious insider threat Negligent insider risk External data breach Compromised insider account 40 / 50 Which of the following best describes the primary purpose of AWS GuardDuty in this scenario? To automatically back up all cloud resources every 24 hours. To monitor cloud activity and detect potential security threats. To manage user roles and permissions within the cloud environment. To optimize the company’s cloud storage usage and reduce cost 41 / 50 The Data Security & Information Lifecycle (DSI) domain ensures data is protected during which of the following stages? Only during storage Only during destruction From creation to destruction Only during sharing Explanation: DSI covers the entire lifecycle: creation, storage, use, sharing, archival, and destruction. 42 / 50 Which scenario BEST demonstrates a failure of the Shared Responsibility Model in a cloud environment? A CSP failing to patch its physical data center servers A customer deploying an application without encrypting stored client data The CSA updating CCM from v3 to v4 A CSP offering MFA as an optional service 43 / 50 OWASP ZAP is primarily used for: Malware detection Web application security testing Network packet sniffing Password cracking 44 / 50 Which security principle is MOST aligned with enforcing least privilege in a zero-trust architecture? Grant full access and monitor post-activity Trust users after initial authentication Continuously verify identity and limit access to required resources only Disable MFA to reduce authentication failures 45 / 50 Which combination of controls would MOST effectively reduce the risk of cloud misconfiguration leading to data exposure? SSO and DLP only RBAC and SIEM tools Configuration baselines with automated audits and least privilege Backup schedules and CCSK training 46 / 50 Which of the following factors MOST contributes to the increased cybersecurity risk posed by IoT devices? IoT devices always operate on isolated networks by default. They frequently use unencrypted communication channels and run unpatched firmware for long periods. Their manufacturers enforce strict update policies across all devices globally. They are usually deployed only in high-security industrial environments. 47 / 50 Disabling compromised credentials immediately Network access rules All components and libraries used by an application Hardware configurations in the cloud User activity logs and flow records 48 / 50 In Secure SDLC, at what stage should security be integrated into the development process? Only before deployment Only during testing At the architecture stage and throughout the lifecycle After the application is fully deployed 49 / 50 What does the Cloud Controls Matrix (CCM) primarily provide? A unified set of cloud security controls mapped across global standards A list of all cloud vendors in the world A tool for encrypting data in the cloud A guide for financial auditing 50 / 50 What is the main objective of the Respond (RS) function in a cybersecurity framework? To prevent all cyber-attacks before they occur. To ensure the organization reacts quickly and effectively, communicates clearly, and performs forensic analysis after an incident. To ensure the organization reacts quickly and effectively, communicates clearly, and performs forensic analysis after an incident. To restore all systems to full operation without analyzing the cause of the incident Your score is 0% Restart quiz