CLOUDSEC-PRO Exam Questions
220 real CLOUDSEC-PRO exam questions with expert-verified answers and explanations. Page 3 of 5.
- Question #101Data Security Posture Management
Which two modules work together to secure sensitive data in cloud workloads? (Choose two)
DSPMCSPMdata securitysensitive data protection - Question #102Vulnerability Management
A benefit of integrating vulnerability management into posture security tools is:
vulnerability managementpatch automationposture integrationdiscovery workflows - Question #103Cloud Workload Protection
Agentless scanning is less effective for detecting:
agentless scanningruntime anomaliesdetection limitationsprocess monitoring - Question #104Compliance and Audit Management
Unified compliance management can reduce audit time by:
compliance automationevidence collectionaudit efficiencycontrol mapping - Question #105Identity and Access Management
Identity security supports compliance by:
identity securityMFAleast privilegecompliance - Question #106Vulnerability Management
Which two functions are typically part of a vulnerability management module? (Choose two)
vulnerability managementasset discoverypatch validation - Question #107Cloud Security Posture Management
Posture Security Management Modules provide value by:
posture securityCSPMsecurity visibility - Question #108Vulnerability Management
A key difference between agent-based and agentless scanning is:
agent-based scanningagentless scanningruntime analysis - Question #109Cloud Security Posture Management
Which two benefits are achieved by combining CSPM with unified compliance management? (Choose two)
CSPMcompliance managementmisconfiguration detectionregulatory reporting - Question #110Identity and Access Management
An IAM security module can prevent lateral movement attacks by:
IAMlateral movementcross-account permissionsprivilege control - Question #111Vulnerability Management
A vulnerability scan shows a critical flaw in an internet-facing workload. The most effective next step is to:
vulnerability remediationpatch managementinternet-facing workloads - Question #112Cloud Workload Protection
Which is the main function of Cloud Workload Protection (CWP)?
cloud workload protectionruntime securitymulti-cloud - Question #113Cloud Workload Protection
Which two capabilities are core to CWP solutions? (Choose two)
CWPruntime threat detectionvulnerability visibility - Question #114Cloud Detection and Response
Cloud Detection and Response (CDR) focuses on:
cloud detection and responsethreat detectionincident response - Question #115Cloud Detection and Response
Which two features are typical of Cloud Detection and Response tools? (Choose two)
CDRanomaly detectionautomated remediation - Question #116Cloud Workload Protection
A security team uses CWP to enforce allowlist policies on container images. This helps to:
CWPcontainer securityallowlist policiesimage validation - Question #117Cloud Workload Protection
Which runtime security capability helps detect privilege escalation attempts inside workloads?
runtime securityprivilege escalationbehavior-based detection - Question #118Cloud Detection and Response
CDR differs from traditional SIEM in that it:
CDRSIEMcloud-native telemetry - Question #119Cloud Workload Protection
Which two workload types are typically protected by CWP? (Choose two)
CWPvirtual machinescontainersworkload protection - Question #120Cloud Detection and Response
A CDR system triggers an alert for an abnormal spike in outbound traffic from a storage bucket. This is likely an example of:
CDRdata exfiltrationanomaly detectionstorage security - Question #121Cloud Workload Protection
Which CWP feature prevents malicious processes from spawning inside workloads?
CWPprocess whitelistingmalicious process prevention - Question #122Cloud Workload Protection
Why is runtime protection important even after workloads pass pre-deployment security scans?
runtime protectionpost-deployment securityzero-day vulnerabilities - Question #123Cloud Detection and Response
Which two data sources are commonly integrated into CDR? (Choose two)
CDRCSP audit logsnetwork flow logsdata sources - Question #124Cloud Workload Protection
CWP helps meet compliance requirements by:
CWPcompliancesecurity baselinesworkload enforcement - Question #125Cloud Workload Protection and Detection & Response
What is a primary advantage of integrating CWP and CDR?
CWPCDRruntime threat detectionautomated response - Question #126Cloud Workload Protection and Detection & Response
Which two CWP functions help mitigate malware risk? (Choose two)
CWPfile integrity monitoringmemory protectionmalware mitigation - Question #127Cloud Workload Protection and Detection & Response
CDR is especially effective against:
CDRaccount takeovercloud-native attacks - Question #128Container Security
In container security, runtime monitoring helps detect:
container securityruntime monitoringprocess execution - Question #129Cloud Workload Protection and Detection & Response
Why is anomaly-based detection important in CDR?
CDRanomaly-based detectionunknown threatssignature-less detection - Question #130Cloud Workload Protection and Detection & Response
Which two runtime security features protect workloads from insider threats? (Choose two)
runtime securityprivilege escalationfile access monitoringinsider threats - Question #131Cloud Workload Protection and Detection & Response
A key limitation of CWP is that:
CWPCI/CD integrationlimitationsmulti-cloud - Question #132Web Application and API Security
Web Application and API Security (WAAS) protects against:
WAASSQL injectionAPI abuseweb application security - Question #133Web Application and API Security
Which two capabilities are core to WAAS? (Choose two)
WAASbot mitigationAPI schema validation - Question #134Vulnerability Management
Vulnerability management in runtime security aims to:
vulnerability managementruntime securityremediationprioritization - Question #135Vulnerability Management
Which two factors are used to prioritize vulnerabilities? (Choose two)
vulnerability prioritizationCVSS scoreexploit availability - Question #136Runtime Security Agent Management
Agent management in runtime security involves:
agent managementsecurity agentsworkload deployment - Question #137Runtime Security Agent Management
Which two challenges are common in agent deployment? (Choose two)
agent deploymentperformance overheadOS compatibility - Question #138Web Application and API Security
WAAS can mitigate credential stuffing attacks by:
WAAScredential stuffingbrute force detectionlogin protection - Question #139Web Application and API Security
Why is API security critical in cloud runtime environments?
API securityattack vectorsunauthorized accesscloud runtime - Question #140Vulnerability Management
A vulnerability scan detects outdated open-source libraries in a container image. The next best step is to:
vulnerability managementcontainer imageopen-source librariespatch remediation - Question #141Vulnerability Management
Which two features are essential in a runtime vulnerability management program? (Choose two)
vulnerability managementcontinuous scanningpatch management integration - Question #142Web Application and API Security
Agentless WAAS deployment is preferred when:
WAASagentless deploymentperformance impact - Question #143Web Application and API Security
Which two capabilities improve WAAS detection accuracy? (Choose two)
WAASallowlistingmachine learninganomaly detection - Question #144Runtime Security Agent Management
Agent management dashboards typically provide:
agent managementdeployment statushealth metricsdashboard - Question #145Runtime Security and Application Protection
What is a disadvantage of over-relying on agent-based WAAS deployment?
WAASagent-based deploymentperformance impactcloud security - Question #146Runtime Security and Application Protection
Which WAAS feature protects against API abuse?
WAASAPI securityrate limitingschema validation - Question #147Vulnerability and Threat Management
A vulnerability in a workload has a CVSS 9.8 score and is actively exploited. What should be the response priority?
CVSS scoringvulnerability managementremediation prioritythreat response - Question #148Runtime Security and Application Protection
In runtime environments, agent deployment failures can result from:
agent deploymentruntime securitykernel compatibilitynetwork connectivity - Question #149Runtime Security and Application Protection
Which two functions are enhanced by integrating WAAS with vulnerability management? (Choose two)
WAASvulnerability managementintegrationremediation - Question #150Runtime Security and Application Protection
Agent lifecycle management includes:
agent lifecycledeploymentmonitoringagent management