✅ Free practice — no sign-up📝 Real exam-style questions💡 Detailed explanations💸 30-day money-back via Udemy
Question 1 of 12 · Cloud Concepts, Architecture and Design
A company migrates a legacy application to an IaaS provider. Under the shared responsibility model, which security responsibility remains with the customer?
In IaaS, the CSP manages the physical infrastructure, network hardware, and hypervisor, while the customer is responsible for the guest OS, middleware, applications, and data.
Question 2 of 12 · Cloud Data Security
A company's retention policy requires that customer records be kept for 7 years after account closure. At the 5-year mark, records are moved from primary object storage to a lower-cost storage tier where they are rarely accessed but must remain retrievable until the retention period expires and secure deletion occurs. Which phase of the cloud secure data lifecycle does this describe?
The CSA/CCSP data lifecycle defines Archive as the phase where data is moved to long-term, lower-cost storage in accordance with retention policy, remaining available but rarely used, prior to eventual destruction.
Question 3 of 12 · Cloud Platform and Infrastructure Security
A retail company migrating its e-commerce platform to the cloud requires an RTO of 4 hours and an RPO of 15 minutes for its order-processing system, while keeping ongoing DR costs as low as possible. Which disaster recovery strategy BEST meets these requirements?
A warm site keeps partially provisioned standby infrastructure ready and replicates data frequently enough (every 15 minutes) to satisfy the RPO, while allowing a few hours for failover activation to meet the RTO — all at a moderate cost, matching the stated cost sensitivity.
Question 4 of 12 · Cloud Application Security
A financial services company has deployed a web application to a staging environment that mirrors production, but the security team has no access to the source code because the application was built by a third-party vendor. The team needs to identify runtime vulnerabilities such as SQL injection and reflected cross-site scripting by interacting with the running application over HTTP. Which testing method BEST meets this requirement?
DAST is a black-box technique that tests a running application from the outside by sending crafted requests and observing responses, requiring no source code access — exactly the scenario described.
Question 5 of 12 · Cloud Security Operations
During an incident investigation of a compromised cloud virtual machine, a security analyst must collect evidence following proper order of volatility. Which item should be collected FIRST?
RAM and running process state are the most volatile artifacts and are lost immediately on reboot or shutdown, so they must be captured before any less volatile evidence.
Question 6 of 12 · Legal, Risk and Compliance
A company based in the EU uses a US-headquartered CSP to process customer personal data. Following the Schrems II ruling, which mechanism should the company implement to legally continue this cross-border transfer?
Post-Schrems II, SCCs remain valid but must be supplemented with a transfer impact assessment evaluating the destination country's surveillance laws, plus technical measures (e.g., encryption with keys held outside the importer's reach) to address risks like US government access under FISA 702.
Question 7 of 12 · Cloud Concepts, Architecture and Design
A group of hospitals in the same region want to share a cloud infrastructure to jointly meet common regulatory requirements, with costs and resources shared only among the participating hospitals. Which deployment model BEST fits this need?
Community cloud infrastructure is provisioned for exclusive use by a specific group of organizations that share common concerns such as mission, security requirements, or regulatory compliance, with costs shared among members.
Question 8 of 12 · Cloud Data Security
A payment processor must replace primary account numbers (PANs) in its cloud database with surrogate values that preserve the original format for downstream billing systems. The original values can only be recovered by an authorized process performing a lookup against a securely isolated vault. Which technique is being used?
Tokenization replaces sensitive data with a non-sensitive surrogate (token) that has no mathematical relationship to the original value; the mapping is stored in a separately secured token vault, which is exactly the PCI DSS-style pattern described.
Question 9 of 12 · Cloud Platform and Infrastructure Security
A cloud security architect is designing controls to protect against an attacker who compromises a single tenant's VM and attempts to escape to the underlying virtualization layer to affect other tenants. Which control should be prioritized FIRST?
VM escape attacks target vulnerabilities in the hypervisor itself; keeping the hypervisor patched and hardened directly closes the attack path that would let a compromised guest VM affect the host or sibling VMs, making it the first-priority control for this specific threat.
Question 10 of 12 · Cloud Application Security
A cloud-hosted application accepts a user-supplied URL to fetch a remote image for processing. An attacker submits the URL 'http://169.254.169.254/latest/meta-data/iam/security-credentials/role-name' and the application returns the instance's temporary IAM credentials in its response. Which solution BEST mitigates this vulnerability going forward?
This is a Server-Side Request Forgery (SSRF) attack targeting the instance metadata service. Requiring IMDSv2 (session-oriented, token-based requests) with a hop limit of 1 prevents the request from being proxied through the vulnerable application, and blocking egress to 169.254.169.254 stops the SSRF path entirely.
Question 11 of 12 · Cloud Security Operations
A cloud service provider (CSP) discovers a security incident affecting multiple tenants' data through a misconfigured shared storage bucket. Per CCSP guidance on stakeholder communication during incidents, what is the BEST immediate action for the CSP?
Contractual SLAs and regulations (e.g., breach notification laws) require timely disclosure to affected parties; notification obligations run in parallel with, not after, investigation.
Question 12 of 12 · Legal, Risk and Compliance
A customer receives a litigation hold notice and must preserve specific data stored in a multi-tenant SaaS application without impacting the data or availability of other tenants sharing the platform. Which approach BEST meets this requirement?
Reputable SaaS providers offer tenant-scoped legal hold/eDiscovery APIs precisely because customers cannot access shared physical infrastructure; using these preserves the required data in place, defensibly, without exposing or disrupting other tenants.
Ready for the real thing?
The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.
The exam fee is approximately $599 and varies by region — confirm current pricing with the certification vendor before you book.
What topics are on the exam?
It covers 6 domains: Cloud Concepts, Architecture and Design (17%), Cloud Data Security (20%), Cloud Platform and Infrastructure Security (17%), Cloud Application Security (16%), Cloud Security Operations (17%), Legal, Risk and Compliance (13%). The full course has a dedicated chapter, lab and practice-test coverage for each.
Is this practice test really free?
Yes — all questions on this page are free with explanations and no sign-up. The paid Udemy course adds two full-length timed exams, video lessons and hands-on labs.
Will this prepare me for the real exam?
The questions mirror the real exam's style and are mapped to the official domains. This is exam-focused preparation — combine the free test with the full course's timed simulations to gauge your readiness.