โ† All CCP Flashcard Decks

Cloud Workload Protection Flashcards

7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Cloud Workload Protection flashcards as text
  1. What is 'container escape' and why is it a critical cloud workload security concern?

    Answer: When an attacker breaks out of a container's isolation boundary to access the underlying host system

    Container escape occurs when an attacker exploits vulnerabilities to break out of container isolation and gain access to the host OS, potentially compromising all workloads on that host.

  2. Which security practice ensures that cloud workload security policies are consistently applied across hundreds of microservices?

    Answer: Policy-as-Code using tools like OPA (Open Policy Agent) integrated into the CI/CD pipeline

    Policy-as-Code automates security policy enforcement at scale, ensuring consistent application of security rules across all microservices without manual intervention.

  3. A security analyst notices a cloud function is making unexpected outbound connections to a cryptocurrency mining pool. This is an example of which threat?

    Answer: Cryptojacking

    Cryptojacking involves attackers hijacking cloud compute resources to mine cryptocurrency, often resulting in unexpected outbound connections to mining pools.

  4. What is the purpose of 'allowlisting' in cloud workload runtime protection?

    Answer: Defining an approved set of processes, binaries, and behaviors that are permitted to run on a workload

    Allowlisting (application control) defines what is explicitly permitted to execute on a workload, blocking any process or behavior not on the approved list.

  5. In a shared responsibility model for cloud workload security, which area remains the customer's responsibility regardless of service type (IaaS, PaaS, SaaS)?

    Answer: Data classification and protection of customer data

    Customers are always responsible for their own data classification and protection, regardless of the cloud service model used.

  6. What does 'zero-trust' mean when applied specifically to cloud workload communication?

    Answer: Every workload must authenticate and authorize every request, even from other internal workloads

    Zero-trust for workloads means mutual authentication and authorization for all service-to-service communication, eliminating implicit trust based on network location.

  7. Which technique is MOST effective for detecting malicious activity in cloud workloads that uses legitimate cloud services (Living-off-the-Land attacks)?

    Answer: Behavioral analytics that establish baselines and detect anomalous usage patterns of cloud APIs and services

    Behavioral analytics detect anomalies in how cloud APIs and services are used, catching attackers who use legitimate tools in malicious ways that evade signature detection.