/50

Cybersecurity & Cloud Computing Exam

Instructions: You have 60 Minutes to complete the exam. Read each question carefully and select the best answer. Ensure you submit before the timer expires.

Begin when ready. Good luck!

Please enter the same email address you used during the class. This helps us verify your identity and record your quiz results correctly.

1 / 50

Which factor most directly links the Cloud Controls Matrix (CCM) to international security
standards?

2 / 50

Under NIST CSF, what is the primary purpose of the “Detect” function?

3 / 50

What does the Cloud Controls Matrix (CCM) primarily provide?

4 / 50

An employee accidentally uploads confidential client data to a publicly accessible cloud bucket. This
incident is BEST classified as:

5 / 50

What is the PRIMARY purpose of network segmentation in security architecture?

6 / 50

Which security principle is MOST aligned with enforcing least privilege in a zero-trust
architecture?

7 / 50

What is the focus of Oversight within the NIST CSF?

8 / 50

An employee accidentally uploads confidential client data to a publicly accessible cloud bucket. The
incident is BEST classified as:

9 / 50

Which of the following is a recommended practice for Encryption & Key Management (EKM)?

10 / 50

Which of the following BEST describes how cybercriminals leverage AI to enhance their attack
capabilities?

11 / 50

In Secure SDLC, at what stage should security be integrated into the development process?

12 / 50

Which combination of controls would MOST effectively reduce the risk of cloud misconfiguration
leading to data exposure?

13 / 50

In the CSA CCM, which domain focuses on controlling user identities, authentication, and access rights?

14 / 50

Which cloud security challenge is Zero Trust designed to address?

15 / 50

What is the primary goal of Vulnerability Assessment and Penetration Testing (VAPT)?

16 / 50

Which of the following best describes the primary purpose of AWS GuardDuty in this
scenario?

17 / 50

The Data Security & Information Lifecycle (DSI) domain ensures data is protected during which of the following stages?

18 / 50

Which STAR level involves independent third-party auditing?

19 / 50

Which scenario BEST illustrates the cybersecurity threat posed by deepfake technology?

20 / 50

What is the main objective of the Respond (RS) function in a cybersecurity
framework?

21 / 50

A developer stores passwords in plain text in the database. Which OWASP Top 10 risk does this represent?

22 / 50

What is the primary purpose of RS.AN (Analysis) in incident response?

23 / 50

What is the first phase of building a cloud security roadmap?

24 / 50

Which IR (Incident Response) stage focuses on identifying abnormal activity through alerts
and logs?

25 / 50

After a ransomware attack on a payment service provider, IT restores clean servers
from offline backups and the security team validates that no malware remains. What
does this activity represent?

26 / 50

Which of the following factors MOST contributes to the increased cybersecurity risk posed by
IoT devices?

27 / 50

OWASP ZAP is primarily used for:

28 / 50

Which of the following aligns with Roles, Responsibilities, and Authorities?

29 / 50

Which Nmap command is used to perform a simple TCP SYN scan?

30 / 50

You want to detect the version of services running on open ports. Which Nmap option should you use?

31 / 50

Which option best fits Cybersecurity Supply Chain Risk Management?

32 / 50

Which of the following BEST explains why quantum computing represents a major
cybersecurity risk?

33 / 50

During a penetration test, you discover a web application vulnerable to SQL injection. Which payload would best confirm the vulnerability?

34 / 50

Which of the following is a short-term containment action in cloud incident response?

35 / 50

Zero Trust Architecture
Modern cybersecurity models have shifted away from perimeter-based assumptions. Zero Trust
Architecture rejects the notion that users or devices within a network are inherently secure. Instead, it requires continuous validation of identity, device health, and permissions.
Which of the following statements BEST reflects the foundation of the Zero Trust security
philosophy?

36 / 50

Which option best describes how DE.CM (Continuous Monitoring) and DE.AE
(Anomalies and Events) work together in a cybersecurity environment?

37 / 50

Disabling compromised credentials immediately

38 / 50

Which incident response phase focuses on identifying lessons learned and improving future
security posture?

39 / 50

Which of the following is a best practice for Identity & Access Management (IAM)?

40 / 50

According to the CSA CCM structure, what is the PRIMARY role of the GRC domain?

41 / 50

Which organization created the Cloud Controls Matrix (CCM) framework for cloud security?

42 / 50

When using OWASP ZAP in man‑in‑the‑middle proxy mode, what is the first step to intercept traffic?

43 / 50

Which scenario BEST demonstrates a failure of the Shared Responsibility Model in a cloud
environment?

44 / 50

What is the primary purpose of the CSA STAR Registry?

45 / 50

Which Kali Linux tool is most suitable for exploiting known vulnerabilities after scanning?

46 / 50

Which OWASP Top 10 risk refers to flaws that allow attackers to execute unauthorized code or commands?

47 / 50

Which statement best describes the purpose of Organizational Context?

48 / 50

Kali Linux is best described as:

49 / 50

What is the goal of the Risk Management Strategy category?

50 / 50

Which function in the NIST Cybersecurity Framework (CSF) focuses on developing
safeguards to limit the impact of cybersecurity events?

Your score is

0%