Certified Cloud Security Engineer v2 Free Sample Questions

20 free sample questions232 in the full practice test

Try simulator

312-40 Sample Questions

  1. Question 1

    A global logistics firm uses a multi-cloud strategy with applications deployed across AWS and Azure. To standardize security monitoring, they are forwarding all logs to a central SIEM. An analyst observes that Azure Activity Logs are being ingested successfully, but AWS CloudTrail logs are not appearing. The AWS environment uses multiple accounts under AWS Organizations, and logs are centrally collected in an S3 bucket in the management account. What is the MOST likely cause of this issue?

    Answer and explanation

    Correct answer: A

    The most probable cause is a permissions issue. When using a central S3 bucket for AWS Organizations' CloudTrail logs, the IAM role or user credentials used by the SIEM's data connector must have the necessary s3:GetObject and s3:ListBucket permissions on that specific bucket. Network ACLs are stateless and less likely to be the root cause for a service-level integration. CloudTrail is enabled by default for management events, so it's unlikely to be disabled. A misconfigured trail would affect log generation, not ingestion by an external system if logs are present in S3.

  2. Question 2

    Multiple answers

    A development team is building a cloud-native application on Google Cloud Platform (GCP) and needs to manage application secrets such as API keys and database credentials. A security architect wants to ensure that secrets are not hardcoded in source code and that access is tightly controlled and audited. Which TWO GCP services should be used together to meet these requirements? (Select TWO).

    Answer and explanation

    Correct answers: A, C

    Secret Manager is GCP's dedicated service for storing, managing, and accessing secrets. It provides versioning, automatic rotation (via Cloud Functions), and integration with other GCP services. IAM is used to define granular permissions, specifying which principals (users, service accounts) can access which secrets.

    IAM provides the authorization mechanism to control access to Secret Manager. You use IAM policies to grant roles like 'Secret Manager Secret Accessor' to specific service accounts or users, enforcing the principle of least privilege. Secret Manager relies on IAM for its access control.

  3. Question 3

    A healthcare startup is deploying its patient portal application in AWS. To comply with HIPAA, all data at rest must be encrypted. A cloud engineer decides to use Server-Side Encryption with AWS KMS-Managed Keys (SSE-KMS) for the S3 buckets storing patient records. True or False: Under the AWS Shared Responsibility Model, AWS is solely responsible for managing the lifecycle and rotation of these KMS keys.

    Answer and explanation

    Correct answer: B

    This statement is false. While AWS manages the physical security and availability of the KMS hardware, the customer is responsible for configuring the key policies (IAM), managing grants, enabling or disabling keys, and configuring automatic key rotation. For SSE-KMS, this is a shared responsibility. The customer defines the key and its access policies; AWS manages the underlying service that performs the encryption.

  4. Question 4

    A financial institution is migrating its on-premises data warehouse to the cloud and has chosen Azure Synapse Analytics. Due to strict regulatory requirements, the security team must ensure that data is encrypted at rest, in transit, and that network access to the Synapse workspace is restricted to a private network. Additionally, they need to prevent data exfiltration by blocking public internet access from the workspace's managed virtual network. Which combination of Azure security features provides the most comprehensive solution to meet all these requirements?

    Answer and explanation

    Correct answer: B

    This is the most comprehensive and secure solution. A Managed VNet isolates the workspace. Data exfiltration protection blocks outbound public internet traffic. Managed Private Endpoints secure connections to other Azure services. A Private Endpoint for the workspace itself ensures all client connections originate from the private network, satisfying all stated requirements.

  5. Question 5

    A retail company has deployed a large-scale e-commerce platform on AWS, using a combination of EC2 instances for the frontend, ECS containers for microservices, and RDS for the database. During a routine audit, the security team is tasked with automating the assessment of hosts for vulnerabilities and unintended network exposure. The solution must be automated, continuously assess the environment, and provide prioritized findings. Which AWS service is specifically designed for this purpose?

    Answer and explanation

    Correct answer: D

    Amazon Inspector is the correct service. It is an automated vulnerability management service that continuously scans AWS workloads (EC2, ECR for containers) for software vulnerabilities and unintended network exposure. It automatically discovers running workloads, scans them, and provides a prioritized list of findings.

  6. Question 6

    During a penetration test of a cloud environment, an ethical hacker gains access to an EC2 instance with an attached IAM role. The tester wants to determine the permissions associated with this role to identify potential privilege escalation paths. Which AWS CLI command should the tester use to retrieve the policies attached to the IAM role from the compromised instance?

    Answer and explanation

    Correct answer: B

    This is the correct command. aws iam list-attached-role-policies --role-name lists the names and ARNs of the managed policies that are attached to the specified IAM role. This is a primary step in enumerating permissions during a penetration test.

  7. Question 7

    A company is designing a disaster recovery (DR) plan for a critical application running in a single AWS Region. The application uses EC2 instances, an RDS database, and S3 for storing static assets. The business requires a Recovery Time Objective (RTO) of less than 1 hour and a Recovery Point Objective (RPO) of 15 minutes. The DR strategy must be cost-effective. Which DR strategy BEST meets these requirements?

    Answer and explanation

    Correct answer: B

    The Pilot Light strategy provides a balance between cost and recovery time. The core infrastructure is running (the 'pilot light'), and data is actively replicated (RDS read replica, S3 CRR), which supports a low RPO. In a disaster, the infrastructure can be scaled out relatively quickly (e.g., via Auto Scaling), meeting the < 1 hour RTO without the cost of a fully scaled-out warm standby environment.

  8. Question 8

    A security analyst is investigating a suspected data breach in their company's AWS environment. They believe an S3 bucket containing sensitive customer data was made public for a short period. To confirm this, the analyst needs to find evidence of PutBucketAcl API calls that changed the bucket's permissions. Which log source should the analyst investigate to find this specific information?

    Answer and explanation

    Correct answer: C

    AWS CloudTrail is the correct source. It provides a record of actions taken by a user, role, or an AWS service. All management API calls, including PutBucketAcl, are recorded in CloudTrail logs, providing the necessary audit trail for forensic investigation of permission changes.

  9. Question 9

    A government agency is deploying a sensitive application on Azure and must comply with the NIST Risk Management Framework (RMF). The agency needs a tool to define and enforce organizational standards, assess compliance at scale, and remediate non-compliant resources. Which Azure service is designed to create, assign, and manage policies that enforce these rules over resources?

    Answer and explanation

    Correct answer: C

    Azure Policy is the correct service. It allows you to create policies that enforce and control the properties of a resource. These policies can enforce rules for resource configuration, such as allowing only certain VM SKUs or requiring tags. It has built-in policy initiatives that map to compliance frameworks like NIST, making it the ideal tool for governance and compliance enforcement.

  10. Question 10

    A cloud security architect needs to design a secure network architecture on AWS for a multi-tier web application. The design must adhere to the principle of least privilege and defense-in-depth. Which of the following represents the BEST implementation using AWS native security controls?

    graph TD subgraph VPC subgraph PublicSubnet ELB[Elastic Load Balancer] end subgraph PrivateSubnet1 Web[Web Servers] end subgraph PrivateSubnet2 App[App Servers] end subgraph PrivateSubnet3 DB[Database] end end Internet --> ELB ELB --> Web Web --> App App --> DB
    Answer and explanation

    Correct answer: C

    This is the ideal implementation. It uses subnetting for network segmentation and granular, stateful Security Groups to enforce the principle of least privilege. Traffic flow is strictly controlled between tiers (ELB -> Web -> App -> DB), providing strong defense-in-depth.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 232 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon