Cloud Workload Protection Flashcards
7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Cloud Workload Protection flashcards as text
Which AWS service provides managed threat detection for EC2 instances, containers, and serverless workloads by analyzing CloudTrail, VPC Flow Logs, and DNS logs?
Answer: AWS GuardDuty
AWS GuardDuty is a managed threat detection service that continuously monitors and analyzes data sources to identify malicious activity across workloads.
What does 'microsegmentation' achieve in a cloud workload protection strategy?
Answer: Creates fine-grained network zones that limit lateral movement between workloads
Microsegmentation enforces granular network access policies between individual workloads, containing breaches and limiting an attacker's ability to move laterally.
A developer accidentally pushes a Docker image containing hardcoded AWS credentials to a public registry. What is the FIRST security action to take?
Answer: Immediately rotate and revoke the exposed credentials
Revoking and rotating the exposed credentials is the highest priority to prevent unauthorized use, as the credentials may already have been harvested.
What is the role of a Software Bill of Materials (SBOM) in cloud workload security?
Answer: It provides an inventory of all software components and dependencies in a workload for vulnerability management
An SBOM lists all components, libraries, and dependencies in a workload, enabling teams to quickly identify affected systems when new vulnerabilities are disclosed.
In Kubernetes security, what does a PodSecurityAdmission (PSA) policy enforce?
Answer: Security standards for pod configurations, such as restricting privileged containers and host namespace access
PodSecurityAdmission enforces security profiles (privileged, baseline, restricted) on pod specs to prevent insecure configurations from being deployed.
Which attack technique involves exploiting a vulnerable dependency in a containerized application's base image to gain unauthorized access?
Answer: Supply chain attack
Supply chain attacks target vulnerable dependencies or base images in the build pipeline to introduce malicious code into production workloads.
What is the security benefit of using ephemeral credentials for cloud workloads compared to long-lived static credentials?
Answer: They automatically expire, reducing the window of opportunity if compromised
Ephemeral credentials have short TTLs and expire automatically, so even if stolen, they cannot be used for extended periods by attackers.