Free 312-40 sample questions
Real questions from the Certified Cloud Security Engineer (CCSE v2) practice bank, with the correct answer and an explanation for each one. No junk, no filler.
Try them in the simulator Same questions, with study, timed and flashcard modes.
Showing 10 of 20 free sample questions.
A development team is building a cloud-native application on Google Cloud Platform (GCP) and needs to manage application secrets such as API keys and database credentials. A security architect wants to ensure that secrets are not hardcoded in source code and that access is tightly controlled and audited. Which TWO GCP services should be used together to meet these requirements? (Select TWO).
A healthcare startup is deploying its patient portal application in AWS. To comply with HIPAA, all data at rest must be encrypted. A cloud engineer decides to use Server-Side Encryption with AWS KMS-Managed Keys (SSE-KMS) for the S3 buckets storing patient records. True or False: Under the AWS Shared Responsibility Model, AWS is solely responsible for managing the lifecycle and rotation of these KMS keys.
A financial institution is migrating its on-premises data warehouse to the cloud and has chosen Azure Synapse Analytics. Due to strict regulatory requirements, the security team must ensure that data is encrypted at rest, in transit, and that network access to the Synapse workspace is restricted to a private network. Additionally, they need to prevent data exfiltration by blocking public internet access from the workspace's managed virtual network. Which combination of Azure security features provides the most comprehensive solution to meet all these requirements?
A retail company has deployed a large-scale e-commerce platform on AWS, using a combination of EC2 instances for the frontend, ECS containers for microservices, and RDS for the database. During a routine audit, the security team is tasked with automating the assessment of hosts for vulnerabilities and unintended network exposure. The solution must be automated, continuously assess the environment, and provide prioritized findings. Which AWS service is specifically designed for this purpose?
During a penetration test of a cloud environment, an ethical hacker gains access to an EC2 instance with an attached IAM role. The tester wants to determine the permissions associated with this role to identify potential privilege escalation paths. Which AWS CLI command should the tester use to retrieve the policies attached to the IAM role from the compromised instance?
A company is designing a disaster recovery (DR) plan for a critical application running in a single AWS Region. The application uses EC2 instances, an RDS database, and S3 for storing static assets. The business requires a Recovery Time Objective (RTO) of less than 1 hour and a Recovery Point Objective (RPO) of 15 minutes. The DR strategy must be cost-effective. Which DR strategy BEST meets these requirements?
A security analyst is investigating a suspected data breach in their company's AWS environment. They believe an S3 bucket containing sensitive customer data was made public for a short period. To confirm this, the analyst needs to find evidence of `PutBucketAcl` API calls that changed the bucket's permissions. Which log source should the analyst investigate to find this specific information?
A government agency is deploying a sensitive application on Azure and must comply with the NIST Risk Management Framework (RMF). The agency needs a tool to define and enforce organizational standards, assess compliance at scale, and remediate non-compliant resources. Which Azure service is designed to create, assign, and manage policies that enforce these rules over resources?
A cloud security architect needs to design a secure network architecture on AWS for a multi-tier web application. The design must adhere to the principle of least privilege and defense-in-depth. Which of the following represents the BEST implementation using AWS native security controls? graph TD subgraph VPC subgraph PublicSubnet ELB[Elastic Load Balancer] end subgraph PrivateSubnet1 Web[Web Servers] end subgraph PrivateSubnet2 App[App Servers] end subgraph PrivateSubnet3 DB[Database] end end Internet --> ELB ELB --> Web Web --> App App --> DB
10 more free samples are waiting
Create a free account to unlock the whole 312-40 sample bank, or get full access to all 232 practice questions in the simulator.