312-40 Sample Questions

312-40 Sample Questions & Answers

Platform and infrastructure security, application protections, and data security share the heaviest weighting, with penetration testing, incident response, forensic investigation, business continuity, and governance, risk, and legal issues filling out the rest.

Launch the full 312-40 simulator →

Showing 10 of 20 free samples.

  1. Question 1Intermediate

    Penetration Testing in Cloud · AWS-specific penetration testing steps

    During a penetration test of a cloud environment, an ethical hacker gains access to an EC2 instance with an attached IAM role. The tester wants to determine the permissions associated with this role to identify potential privilege escalation paths. Which AWS CLI command should the tester use to retrieve the policies attached to the IAM role from the compromised instance?

    Show answer & explanation

    Correct answer: B

    This is the correct command. aws iam list-attached-role-policies --role-name lists the names and ARNs of the managed policies that are attached to the specified IAM role. This is a primary step in enumerating permissions during a penetration test.

  2. Question 2Advanced

    Business Continuity and Disaster Recovery in Cloud · Architect Recovery and Resilience in AWS

    A company is designing a disaster recovery (DR) plan for a critical application running in a single AWS Region. The application uses EC2 instances, an RDS database, and S3 for storing static assets. The business requires a Recovery Time Objective (RTO) of less than 1 hour and a Recovery Point Objective (RPO) of 15 minutes. The DR strategy must be cost-effective. Which DR strategy BEST meets these requirements?

    Show answer & explanation

    Correct answer: B

    The Pilot Light strategy provides a balance between cost and recovery time. The core infrastructure is running (the 'pilot light'), and data is actively replicated (RDS read replica, S3 CRR), which supports a low RPO. In a disaster, the infrastructure can be scaled out relatively quickly (e.g., via Auto Scaling), meeting the < 1 hour RTO without the cost of a fully scaled-out warm standby environment.

  3. Question 3Intermediate

    Forensic Investigation in Cloud · Investigate security incidents in Amazon Web Services (AWS)

    A security analyst is investigating a suspected data breach in their company's AWS environment. They believe an S3 bucket containing sensitive customer data was made public for a short period. To confirm this, the analyst needs to find evidence of PutBucketAcl API calls that changed the bucket's permissions. Which log source should the analyst investigate to find this specific information?

    Show answer & explanation

    Correct answer: C

    AWS CloudTrail is the correct source. It provides a record of actions taken by a user, role, or an AWS service. All management API calls, including PutBucketAcl, are recorded in CloudTrail logs, providing the necessary audit trail for forensic investigation of permission changes.

  4. Question 4Intermediate

    Governance, Risk Management, and Compliance in Cloud · GRC in Azure

    A government agency is deploying a sensitive application on Azure and must comply with the NIST Risk Management Framework (RMF). The agency needs a tool to define and enforce organizational standards, assess compliance at scale, and remediate non-compliant resources. Which Azure service is designed to create, assign, and manage policies that enforce these rules over resources?

    Show answer & explanation

    Correct answer: C

    Azure Policy is the correct service. It allows you to create policies that enforce and control the properties of a resource. These policies can enforce rules for resource configuration, such as allowing only certain VM SKUs or requiring tags. It has built-in policy initiatives that map to compliance frameworks like NIST, making it the ideal tool for governance and compliance enforcement.

  5. Question 5Advanced

    Platform and Infrastructure Security in Cloud · Design a Secure Data Center in Cloud

    A cloud security architect needs to design a secure network architecture on AWS for a multi-tier web application. The design must adhere to the principle of least privilege and defense-in-depth. Which of the following represents the BEST implementation using AWS native security controls?

    graph TD subgraph VPC subgraph PublicSubnet ELB[Elastic Load Balancer] end subgraph PrivateSubnet1 Web[Web Servers] end subgraph PrivateSubnet2 App[App Servers] end subgraph PrivateSubnet3 DB[Database] end end Internet --> ELB ELB --> Web Web --> App App --> DB
    Show answer & explanation

    Correct answer: C

    This is the ideal implementation. It uses subnetting for network segmentation and granular, stateful Security Groups to enforce the principle of least privilege. Traffic flow is strictly controlled between tiers (ELB -> Web -> App -> DB), providing strong defense-in-depth.

  6. Question 6Intermediate

    Standards, Policies, and Legal Issues in Cloud · Legal Frameworks for Data Protection and Privacy

    A European company must ensure its use of cloud services complies with GDPR. A key requirement is ensuring that personal data of EU citizens does not leave specific geographic boundaries unless adequate data protection measures are in place. Which legal and technical concept is MOST critical for the company to address when configuring their cloud environment?

    Show answer & explanation

    Correct answer: A

    Data sovereignty is the concept that information which has been converted and stored in binary digital form is subject to the laws of the country in which it is located. For GDPR compliance, this means ensuring EU citizen data is stored and processed within designated regions (like EU regions offered by cloud providers) to comply with legal requirements about data residency and cross-border transfers.

  7. Question 7IntermediateSelect 3

    Application Security in Cloud · DevOps and Continuous Integration/Continuous Deployment (CI/CD)

    A security team is implementing a DevSecOps pipeline for a containerized application deployed on Azure Kubernetes Service (AKS). To prevent vulnerable images from being deployed, they need to integrate an automated scanning process. At which stage of the CI/CD pipeline should container image vulnerability scanning be performed? (Select ALL that apply).

    Show answer & explanation

    Correct answers: A, B, C

    Scanning during the build phase ('shift left') is a critical best practice. It provides the earliest possible feedback to developers, allowing them to fix vulnerabilities before the image is even stored in a registry.

    Scanning images in the registry is essential. Most registries, like ACR, have built-in scanning capabilities. This ensures that even images built outside the pipeline are checked and provides a continuous assessment for newly discovered vulnerabilities in existing images.

    Runtime scanning is another layer of defense. It can detect vulnerabilities in running containers that might have been missed, or it can identify malicious processes and activities. Services like Microsoft Defender for Containers provide this capability.

  8. Question 8Beginner

    Introduction to Cloud Security · Cloud Computing Fundamentals

    A cloud architect is evaluating different cloud service models for hosting a new custom application. The development team wants to focus solely on writing code and managing application data, without worrying about the underlying operating system, patching, or runtime environment. Which cloud service model BEST fits this requirement?

    Show answer & explanation

    Correct answer: B

    Platform as a Service (PaaS) is the correct model. It provides a platform allowing customers to develop, run, and manage applications without the complexity of building and maintaining the infrastructure typically associated with developing and launching an app. The cloud provider manages the OS, patching, and runtime, letting developers focus on their application code and data.

  9. Question 9Intermediate

    Data Security in Cloud · Cloud storage architecture and lifecycle phases

    A media company stores large video files in Google Cloud Storage. To reduce costs, they have implemented a lifecycle policy to transition objects to the Archive Storage class after 365 days. A video editor now needs to access a 3-year-old video file for a retrospective project. What is the process for accessing this archived object?

    Show answer & explanation

    Correct answer: B

    Correct. Objects in Google's Archive Storage are offline and must be restored before they can be accessed. Initiating a restore operation creates a temporary, cached copy of the object that becomes available for access after a few hours. The original archived object remains.

  10. Question 10Intermediate

    Incident Response in Cloud · Cloud Incident Response Lifecycle

    A SOC analyst receives an alert from Microsoft Defender for Cloud indicating that a virtual machine in Azure is communicating with a known malicious IP address associated with a command-and-control (C2) server. This is the first step in the incident response process. According to the standard incident response lifecycle, what is the IMMEDIATE next step the analyst should take?

    Show answer & explanation

    Correct answer: C

    After detection and initial analysis, the immediate priority is Containment. This involves isolating the compromised system to prevent the threat from spreading to other parts of the network. This could be done by applying a restrictive Network Security Group (NSG) or moving the VM to an isolated VNet.

Ready for the real thing?

The full 312-40 simulator has every exam-style question, timed mode, and instant scoring.

Go to the 312-40 simulator →