Cloud Workload Protection Flashcards
7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Cloud Workload Protection flashcards as text
Which technology provides runtime protection for containerized workloads by monitoring system calls and blocking anomalous behavior?
Answer: Runtime Application Self-Protection (RASP)
RASP monitors and intercepts system calls at runtime to detect and block anomalous behavior within containerized workloads.
A security team discovers that a cloud VM is exfiltrating data to an unknown IP address. What is the BEST immediate containment action?
Answer: Isolate the VM using security group rules to block outbound traffic
Isolating the VM via security group rules stops the exfiltration while preserving forensic evidence for investigation.
What is the primary purpose of a Cloud Workload Protection Platform (CWPP)?
Answer: To provide visibility and protection for workloads across hybrid and multi-cloud environments
CWPPs are designed to secure workloads (VMs, containers, serverless) across hybrid and multi-cloud environments with unified visibility.
In the context of cloud workload protection, what does 'shift-left security' mean?
Answer: Integrating security earlier in the software development lifecycle
Shift-left security means incorporating security controls and testing earlier in the CI/CD pipeline rather than only at deployment.
Which serverless security concern is unique compared to traditional VM-based workload protection?
Answer: Ephemeral execution environment making persistent agent-based protection impractical
Serverless functions are ephemeral and short-lived, making traditional persistent agent-based security tools impractical for protection.
What is a 'golden image' in the context of cloud workload security?
Answer: A hardened, pre-approved VM or container image used as a secure baseline for deployments
A golden image is a hardened, security-vetted baseline image that serves as the approved template for cloud workload deployments.
Which approach best addresses the security challenge of workloads that auto-scale dynamically in cloud environments?
Answer: Immutable infrastructure with security baked into the image pipeline
Immutable infrastructure ensures every auto-scaled instance starts from a pre-hardened image, eliminating configuration drift and manual security gaps.