Cloud-Security-Professional Sample Questions

Cloud-Security-Professional Sample Questions & Answers

Built around cloud security posture management, the single biggest weight, plus runtime security and agent deployment, application security features and use cases, Cortex Cloud components and dashboards, and SOC fundamentals like threat intelligence.

Launch the full Cloud-Security-Professional simulator →

Showing 10 of 20 free samples.

  1. Question 1Beginner

    Cloud Posture Security · 3.1.3 Al Security Posture Management (AI-SPM)

    True or False: The primary function of AI Security Posture Management (AI-SPM) in Cortex Cloud is to use AI to detect misconfigurations in standard cloud resources like storage buckets and virtual machines.

    Show answer & explanation

    Correct answer: B

    This statement is false. Using AI to detect misconfigurations in standard cloud resources is a function of advanced CSPM. The primary function of AI-SPM is to secure the AI models and pipelines themselves, protecting against risks like model theft, data poisoning, and insecure configurations of AI/ML services (e.g., Azure Machine Learning, Amazon SageMaker).

  2. Question 2Advanced

    Cloud Posture Security · 3.1.7 Identity security

    Case Study:

    A rapidly growing e-commerce company, ShopFast, has deployed its entire infrastructure on Google Cloud Platform (GCP). Their environment consists of a Kubernetes cluster (GKE) for microservices, Cloud SQL for databases, and Cloud Storage for static assets. The CISO is concerned about the company's identity and access management posture after a security audit revealed numerous service accounts with overly permissive, project-level roles like 'Editor'. The goal is to enforce the principle of least privilege without disrupting critical application functions.

    The security team uses Cortex Cloud for posture management. They need to identify all service accounts that have permissions they have never used and automatically generate recommendations for tightened IAM policies. The team must then be able to review these recommendations and apply them in a safe, controlled manner.

    Which Cortex Cloud capability is specifically designed to address this requirement?

    Show answer & explanation

    Correct answer: D

    The scenario described is the core use case for Cloud Infrastructure Entitlement Management (CIEM), which is a key part of the Identity Security module. CIEM analyzes actual usage data (e.g., from GCP audit logs) to determine which permissions granted to an identity (like a service account) are excessive because they have never been used. It then automatically generates right-sized, least-privilege IAM policies that can be reviewed and applied, directly addressing the CISO's requirements.

  3. Question 3Intermediate

    Cloud Runtime Security · 4.1.3 Web Application and API Security (WAAS)

    A security engineer is configuring a WAAS policy in Cortex Cloud to protect a web application from OWASP Top 10 threats. The application uses a custom HTTP header, X-Transaction-ID, to track user sessions. A recent penetration test showed that this header is vulnerable to SQL injection. How should the engineer configure the WAAS policy to specifically mitigate this vulnerability without affecting other headers?

    Show answer & explanation

    Correct answer: C

    While default protections are good, a targeted vulnerability in a custom header requires a specific rule. The most precise and effective method is to create a custom WAAS rule that singles out the X-Transaction-ID header and applies SQL injection pattern matching only to its value. This ensures the vulnerability is mitigated without the performance overhead or potential for false positives that might come from inspecting every header with the same level of scrutiny.

  4. Question 4Intermediate

    Cloud Runtime Security · Explain the process of agent management and deployment

    A cloud administrator is tasked with deploying Cortex Host Defenders to a fleet of 500 virtual machines running in Azure. The goal is to automate the deployment process fully, ensuring that any new VM added to a specific resource group is automatically protected. Which deployment method should be used?

    Show answer & explanation

    Correct answer: B

    Azure VM Extensions are the native and most effective way to automate the deployment and lifecycle management of software on Azure VMs. Cortex Cloud provides a specific VM Extension for the Host Defender. This method allows the administrator to define the deployment declaratively (e.g., in an ARM template or via Azure Policy) and ensures that the agent is automatically installed on both existing and future VMs within the targeted scope, fulfilling the automation requirement.

  5. Question 5Intermediate

    Application Security · 5.1.4 Infrastructure as Code (laC) security

    A security team is using Cortex Cloud's IaC scanning to secure its Terraform code before deployment. The scanner flags a resource for having a hardcoded password. Which Terraform feature should the team use to manage this secret securely and resolve the IaC scan finding?

    resource "aws_db_instance" "default" {
    allocated_storage = 10
    engine = "mysql"
    engine_version = "5.7"
    instance_class = "db.t3.micro"
    name = "mydb"
    username = "foo"
    password = "____" # IaC Scanner flags this line
    parameter_group_name = "default.mysql5.7"
    skip_final_snapshot = true
    }
    
    Show answer & explanation

    Correct answer: D

    The best practice for managing secrets in Terraform is to never hardcode them. Instead, you should use a Terraform data source to dynamically fetch the secret from a secure, external secrets management system (e.g., AWS Secrets Manager, Azure Key Vault, HashiCorp Vault) at runtime. This approach prevents the secret from being stored in source control, resolves the IaC scanner finding, and aligns with security best practices.

  6. Question 6BeginnerSelect 3

    Cortex Fundamentals · Explain the process of creating and managing reports and dashboards in Cortex Cloud

    A SOC manager needs to create a custom dashboard in Cortex Cloud to provide executive leadership with a high-level overview of the organization's cloud security posture. Which THREE widgets would be most appropriate for this type of dashboard? (Select THREE)

    Show answer & explanation

    Correct answers: B, D, F

  7. Question 7Intermediate

    Application Security · 5.1.1 Application security posture management (ASPM)

    When implementing Application Security Posture Management (ASPM), what is the primary goal of correlating findings from different security scanning tools (SAST, DAST, SCA)?

    Show answer & explanation

    Correct answer: D

    The core purpose of ASPM is to ingest data from various application security tools to de-duplicate findings, correlate related vulnerabilities, and provide a single, prioritized list of risks. By understanding that a vulnerable library (from SCA) is being used in a piece of code with a known flaw (from SAST) that is exposed in a running application (from DAST), ASPM can assign a much more accurate risk score and help teams focus on the most critical issues first.

  8. Question 8Beginner

    Security Operations Center (SOC) Fundamentals · Explain the role of threat intelligence in incident response and incident management

    A company is migrating its threat intelligence platform to integrate with Cortex Cloud. The goal is to automatically enrich security incidents with contextual data from Unit 42 and other third-party feeds. Which SOC function is primarily responsible for managing this integration and ensuring the intelligence is actionable?

    Show answer & explanation

    Correct answer: B

    Threat Intelligence Management is the specific SOC function dedicated to the collection, processing, analysis, and dissemination of threat intelligence. This includes managing threat feeds, integrating them with security tools like SIEM or CDR platforms, and ensuring that the Indicators of Compromise (IOCs) and contextual data are properly used to enrich alerts and support incident response and threat hunting activities.

  9. Question 9Intermediate

    Cortex Fundamentals · 2.1.1 Users, roles, IP address, domain, and URL indicator types

    A Cortex Cloud administrator needs to provide a team of auditors with read-only access to compliance reports and posture security findings for a specific set of cloud accounts. The auditors must not be able to view data from any other accounts or make any configuration changes. What is the most secure and efficient way to configure this access?

    Show answer & explanation

    Correct answer: C

    This approach correctly applies the principle of least privilege. Creating a custom role allows for granular control over permissions, ensuring the auditors have only the 'read-only' access they need. Scoping this role to specific cloud account groups ensures they can only see data from the accounts they are assigned to audit. This is far more secure and efficient than manual methods or using overly permissive built-in roles.

  10. Question 10Beginner

    Cloud Posture Security · 3.1.5 Agentless scanning

    True or False: Agentless scanning for vulnerability management provides the same level of real-time threat detection for running processes as an agent-based Cloud Workload Protection (CWP) solution.

    Show answer & explanation

    Correct answer: B

    This statement is false. Agentless scanning works by analyzing snapshots of workloads at a point in time. It is excellent for identifying vulnerabilities in installed packages and misconfigurations. However, it has no visibility into active processes, network connections, or file system activity in real-time. An agent-based CWP solution (Defender) runs on the workload itself and is required for real-time detection of malicious runtime behavior.

Ready for the real thing?

The full Cloud-Security-Professional simulator has every exam-style question, timed mode, and instant scoring.