โ† All CCP Flashcard Decks

Cloud Workload Protection Flashcards

7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Cloud Workload Protection flashcards as text
  1. Which AWS service provides managed threat detection for EC2 instances, containers, and serverless workloads by analyzing CloudTrail, VPC Flow Logs, and DNS logs?

    Answer: AWS GuardDuty

    AWS GuardDuty is a managed threat detection service that continuously monitors and analyzes data sources to identify malicious activity across workloads.

  2. What does 'microsegmentation' achieve in a cloud workload protection strategy?

    Answer: Creates fine-grained network zones that limit lateral movement between workloads

    Microsegmentation enforces granular network access policies between individual workloads, containing breaches and limiting an attacker's ability to move laterally.

  3. A developer accidentally pushes a Docker image containing hardcoded AWS credentials to a public registry. What is the FIRST security action to take?

    Answer: Immediately rotate and revoke the exposed credentials

    Revoking and rotating the exposed credentials is the highest priority to prevent unauthorized use, as the credentials may already have been harvested.

  4. What is the role of a Software Bill of Materials (SBOM) in cloud workload security?

    Answer: It provides an inventory of all software components and dependencies in a workload for vulnerability management

    An SBOM lists all components, libraries, and dependencies in a workload, enabling teams to quickly identify affected systems when new vulnerabilities are disclosed.

  5. In Kubernetes security, what does a PodSecurityAdmission (PSA) policy enforce?

    Answer: Security standards for pod configurations, such as restricting privileged containers and host namespace access

    PodSecurityAdmission enforces security profiles (privileged, baseline, restricted) on pod specs to prevent insecure configurations from being deployed.

  6. Which attack technique involves exploiting a vulnerable dependency in a containerized application's base image to gain unauthorized access?

    Answer: Supply chain attack

    Supply chain attacks target vulnerable dependencies or base images in the build pipeline to introduce malicious code into production workloads.

  7. What is the security benefit of using ephemeral credentials for cloud workloads compared to long-lived static credentials?

    Answer: They automatically expire, reducing the window of opportunity if compromised

    Ephemeral credentials have short TTLs and expire automatically, so even if stolen, they cannot be used for extended periods by attackers.