TechNuggets Academy

Securing the Cloud

Free Implementing and Operating Cisco Security Core Technologies practice — 6 questions on Securing the Cloud, with explanations. No sign-up. Full 12-question mixed test →

Question 1 of 6 · Domain 3: Securing the Cloud
A company runs a fleet of Linux virtual machines on Amazon EC2 (IaaS). According to the cloud shared responsibility model, which security task remains the customer's responsibility rather than the cloud provider's?
In IaaS, the provider secures the physical infrastructure, hypervisor, and host network, but the customer owns everything from the guest OS upward, including OS patching, security group rules, and application/data security.
Question 2 of 6 · Domain 3: Securing the Cloud
A security team needs to discover unsanctioned SaaS applications being used by employees, apply DLP controls to files stored in Google Workspace and Microsoft 365, and detect anomalous user login behavior across multiple SaaS platforms via API integration. Which Cisco solution should be deployed?
Cisco Cloudlock is Cisco's CASB, delivering API-based SaaS app discovery, DLP for cloud-stored data, and user and entity behavior analytics (UEBA) across sanctioned SaaS applications.
Question 3 of 6 · Domain 3: Securing the Cloud
An engineer deploys Cisco Secure Workload software agents to a set of production Linux servers. The agents must not only report detailed process- and flow-level telemetry, but also program the host's native firewall (iptables) to enforce microsegmentation policy generated from the application dependency map. Which agent type must be installed?
The Enforcement Agent in Cisco Secure Workload both collects deep visibility telemetry and programs the host-based firewall to enforce segmentation policy pushed down from the platform.
Question 4 of 6 · Domain 3: Securing the Cloud
A security team must build a process-level allow-list policy based on observed communication patterns between microservices running in Kubernetes pods spread across AWS and an on-premises data center, then automatically enforce that policy as workloads scale. Which Cisco capability best satisfies this requirement?
Secure Workload's ADM automatically profiles process- and port-level communication between application tiers/pods and generates a fine-grained allow-list microsegmentation policy that is enforced consistently as workloads scale across hybrid environments.
Question 5 of 6 · Domain 3: Securing the Cloud
Which statement correctly differentiates a CASB solution such as Cisco Cloudlock from cloud security posture/network anomaly capabilities such as those in Cisco Secure Cloud Analytics?
CASB (Cloudlock) governs SaaS data and user behavior via API integrations, whereas Secure Cloud Analytics ingests cloud provider flow logs (e.g., VPC Flow Logs) to baseline network behavior and detect anomalies/misconfigurations in IaaS environments — they address different layers of cloud risk.
Question 6 of 6 · Domain 3: Securing the Cloud
A company has migrated several workloads to AWS EC2 instances and wants to enforce consistent DNS-layer security and Layer 3/4 cloud-delivered firewall policy on all outbound internet traffic from these instances, without deploying or managing dedicated physical or virtual firewall appliances. Which Cisco solution meets this requirement?
Cisco Umbrella provides cloud-delivered DNS-layer security plus a Cloud-Delivered Firewall (CDFW) that enforces Layer 3/4 policy on outbound traffic as a fully cloud-hosted service, requiring no appliance deployment or management by the customer.
Ready for the real thing?

The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.

Start my full course on Udemy →