โ† All CCP Flashcard Decks

Cloud Workload Protection Flashcards

7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Cloud Workload Protection flashcards as text
  1. Which technology provides runtime protection for containerized workloads by monitoring system calls and blocking anomalous behavior?

    Answer: Runtime Application Self-Protection (RASP)

    RASP monitors and intercepts system calls at runtime to detect and block anomalous behavior within containerized workloads.

  2. A security team discovers that a cloud VM is exfiltrating data to an unknown IP address. What is the BEST immediate containment action?

    Answer: Isolate the VM using security group rules to block outbound traffic

    Isolating the VM via security group rules stops the exfiltration while preserving forensic evidence for investigation.

  3. What is the primary purpose of a Cloud Workload Protection Platform (CWPP)?

    Answer: To provide visibility and protection for workloads across hybrid and multi-cloud environments

    CWPPs are designed to secure workloads (VMs, containers, serverless) across hybrid and multi-cloud environments with unified visibility.

  4. In the context of cloud workload protection, what does 'shift-left security' mean?

    Answer: Integrating security earlier in the software development lifecycle

    Shift-left security means incorporating security controls and testing earlier in the CI/CD pipeline rather than only at deployment.

  5. Which serverless security concern is unique compared to traditional VM-based workload protection?

    Answer: Ephemeral execution environment making persistent agent-based protection impractical

    Serverless functions are ephemeral and short-lived, making traditional persistent agent-based security tools impractical for protection.

  6. What is a 'golden image' in the context of cloud workload security?

    Answer: A hardened, pre-approved VM or container image used as a secure baseline for deployments

    A golden image is a hardened, security-vetted baseline image that serves as the approved template for cloud workload deployments.

  7. Which approach best addresses the security challenge of workloads that auto-scale dynamically in cloud environments?

    Answer: Immutable infrastructure with security baked into the image pipeline

    Immutable infrastructure ensures every auto-scaled instance starts from a pre-hardened image, eliminating configuration drift and manual security gaps.