Cloud Workload Protection Flashcards
7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Cloud Workload Protection flashcards as text
What is the significance of eBPF (extended Berkeley Packet Filter) in modern cloud workload security?
Answer: It enables low-overhead kernel-level visibility into workload behavior without modifying application code
eBPF allows security tools to observe system calls, network activity, and process behavior at the kernel level with minimal performance overhead.
A company uses Kubernetes. Which resource defines the network traffic rules allowed between pods?
Answer: NetworkPolicy
Kubernetes NetworkPolicy resources define ingress and egress rules that control traffic flow between pods, enabling micro-segmentation.
What is 'lateral movement' in the context of a cloud workload breach?
Answer: An attacker moving from one compromised workload to other systems within the environment
Lateral movement occurs when an attacker uses a compromised workload as a pivot point to access other systems or data within the cloud environment.
Which cloud workload protection control BEST prevents privilege escalation attacks within a container?
Answer: Running containers as non-root with read-only file systems and dropped Linux capabilities
Running containers as non-root, with read-only file systems and minimal Linux capabilities, significantly limits an attacker's ability to escalate privileges.
In cloud workload security, what is 'drift detection'?
Answer: Identifying changes to a workload's configuration or state that deviate from its approved baseline
Drift detection identifies when a running workload's configuration, files, or behavior has changed from its approved secure baseline.
A security engineer wants to prevent a compromised container from accessing the EC2 instance metadata service. What is the MOST effective control?
Answer: Block the metadata endpoint (169.254.169.254) using iptables rules or IMDSv2 enforcement
Blocking access to the metadata service endpoint prevents containers from retrieving instance credentials that could be used for further attacks.
What is the primary security advantage of using image signing in a container supply chain?
Answer: It ensures only cryptographically verified, trusted images are deployed to production
Image signing (e.g., using Notary or Cosign) ensures integrity and authenticity so only approved images from trusted sources reach production.