
CrowdStrikeCertified Cloud Specialist (CCCS)
Domain 6Objective 1
6.1 Evaluate Cloud Security Controls and Configurations to Identify Indicators of Misconfiguration (IOMs), Vulnerabilities And/or High-Risk Practices CCCS Practice Questions (Page 3)
Part of the Findings and Detection Analysis domain, which makes up ~22% of our current practice bank.
25questions here
5free pages
6concepts
Questions 11–15
- 11
A cloud security team implements a solution that sends alerts when a storage bucket is made publicly accessible. Which category of cloud security control does this represent?
Select an answer first - 12
A company's cloud environment has a web application that stores sensitive customer data in a database. The security team notices that the database's security group allows inbound traffic from 0.0.0.0/0 on port 3306 (MySQL). Which control should be implemented to reduce the risk of unauthorized access?
Select an answer first - 13
During a cloud security assessment, an analyst finds that a storage account has 'Allow Blob public access' enabled, and the container has 'Public access level' set to 'Container'. The storage account is used to store internal financial reports. Which IOM is present?
Select an answer first - 14
A security analyst is reviewing a cloud environment and finds that a virtual network has a network security group (NSG) that allows inbound RDP traffic from the internet. The NSG is associated with a subnet that contains only a web server. Which finding is most appropriate?
Select an answer first - 15
During an assessment, a security team discovers that a virtual machine has a public IP address and is directly reachable from the internet on port 22 (SSH). The VM's operating system is missing critical security patches. Which combination of findings best describes this situation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCCS” is a trademark of its owner, used for identification only.