SPC Unit 1: Questions & Answers
Unit 1: Fundamentals of Cloud Security, Design and Architecture for Cloud -> Generated and Prepared By Thiruselvan (ThiruXD)
Multiple Choice Questions (MCQs) – 50
1. Which of the following best describes the shared responsibility model in cloud security?
a) Cloud provider is fully responsible for all security
b) Customer is fully responsible for all security
c) Security responsibilities are divided between cloud provider and customer
d) Only the network layer is secured by the provider
Answer: c
2. The primary goal of cloud security is to protect:
a) Only physical servers
b) Confidentiality, Integrity, and Availability of data and services
c) Only the hypervisor
d) Only application code
Answer: b
3. Which security service in cloud computing provides protection against unauthorized access to resources?
a) Encryption
b) Identity and Access Management (IAM)
c) Load balancing
d) Auto-scaling
Answer: b
4. One of the key security design principles for cloud computing is:
a) Security through obscurity
b) Defense in depth
c) Single point of failure
d) Open access by default
Answer: b
5. Comprehensive data protection in the cloud primarily focuses on:
a) Only network firewalls
b) Protecting data at rest, in transit, and in use
c) Only physical security of data centers
d) Only application-level logging
Answer: b
6. End-to-end access control ensures:
a) Access is controlled only at the network perimeter
b) Access decisions are enforced consistently from user to resource
c) Only administrators have access
d) Access is granted based solely on IP address
Answer: b
7. A common attack vector in cloud environments is:
a) Physical theft of servers only
b) Misconfigured storage buckets leading to data exposure
c) Only DDoS on on-premise systems
d) Hardware failure
Answer: b
8. Network security in cloud typically includes:
a) Only physical cabling protection
b) Virtual Private Clouds (VPCs), security groups, and network ACLs
c) Only antivirus on endpoints
d) Only email filtering
Answer: b
9. Secure isolation strategies aim to:
a) Share all resources freely among tenants
b) Prevent one tenant from accessing another tenant’s resources or data
c) Disable all virtualization
d) Allow unrestricted inter-tenant communication
Answer: b
10. Virtualization strategies for security include:
a) Running all VMs with the same privileges
b) Using hypervisors with strong isolation and minimising the attack surface
c) Disabling snapshots
d) Sharing memory pages without protection
Answer: b
11. Inter-tenant network segmentation is primarily achieved through:
a) Shared broadcast domains
b) Virtual networks, VLANs, VXLANs, or software-defined networking
c) Physical air-gapping only
d) Disabling all networking
Answer: b
12. Data protection strategies in cloud include:
a) Only deleting data after 1 year
b) Encryption, access controls, and data classification
c) Storing all data in plaintext
d) Sharing encryption keys publicly
Answer: b
13. Data retention, deletion, and archiving procedures must ensure:
a) Data can never be deleted
b) Secure deletion (crypto-shredding or overwriting) and compliance with policies
c) Data is archived without encryption
d) Immediate deletion without logs
Answer: b
14. Which encryption technique is commonly used for data at rest in cloud storage?
a) Only symmetric encryption with keys stored in the same bucket
b) Server-side or client-side encryption using AES
c) No encryption is needed
d) Only hashing
Answer: b
15. Data redaction is the process of:
a) Encrypting the entire dataset
b) Removing or masking sensitive information from documents or logs
c) Compressing data
d) Replicating data across regions
Answer: b
16. Tokenization replaces sensitive data with:
a) The same data in encrypted form
b) Non-sensitive surrogate values (tokens) that map back to the original data
c) Random noise without mapping
d) Hashes only
Answer: b
17. Obfuscation in the context of data protection typically means:
a) Making data completely unreadable without a key
b) Deliberately making data harder to understand or reverse-engineer while preserving usability
c) Deleting data
d) Compressing data
Answer: b
18. Public Key Infrastructure (PKI) provides:
a) Only symmetric keys
b) Digital certificates, public-key cryptography, and certificate authorities for trust
c) Only password storage
d) Only network routing
Answer: b
19. Key management in cloud includes:
a) Storing keys in plaintext in the same storage as data
b) Secure generation, storage, rotation, and destruction of cryptographic keys
c) Sharing keys with all tenants
d) Never rotating keys
Answer: b
20. Which of the following is a fundamental security design principle?
a) Least privilege
b) Maximum privilege by default
c) Trust everyone
d) No auditing
Answer: a
21. Security services in cloud computing commonly include:
a) Only compute services
b) Identity management, encryption, threat detection, and compliance tools
c) Only storage services
d) Only networking without security
Answer: b
22. A major threat in multi-tenant cloud environments is:
a) Side-channel attacks between co-located VMs
b) Only natural disasters
c) Only power outages
d) Hardware upgrades
Answer: a
23. Secure isolation can be achieved at which layers?
a) Only application layer
b) Compute (hypervisor), network, and storage layers
c) Only physical layer
d) Only user interface
Answer: b
24. Virtualization security risks include:
a) Hypervisor vulnerabilities and VM escape
b) Only slow performance
c) Only high cost
d) Only lack of scalability
Answer: a
25. Inter-tenant network segmentation prevents:
a) Legitimate communication between services of the same tenant
b) Unauthorized lateral movement between different tenants
c) All network traffic
d) Internet access
Answer: b
26. Data retention policies in cloud should consider:
a) Legal, regulatory, and business requirements
b) Only storage cost
c) Only performance
d) Unlimited retention always
Answer: a
27. Crypto-shredding refers to:
a) Physically destroying hard drives
b) Destroying encryption keys so that encrypted data becomes unrecoverable
c) Overwriting data multiple times without encryption
d) Compressing data
Answer: b
28. Client-side encryption means:
a) Data is encrypted by the cloud provider
b) Data is encrypted by the customer before being sent to the cloud
c) No encryption is used
d) Only network encryption
Answer: b
29. Tokenization is particularly useful for:
a) Protecting credit card numbers and other sensitive identifiers while allowing processing
b) Encrypting entire databases only
c) Speeding up queries
d) Compressing logs
Answer: a
30. Obfuscation techniques can include:
a) Code obfuscation, data masking, and format-preserving encryption
b) Only full disk encryption
c) Only deleting files
d) Only changing file names
Answer: a
31. In PKI, a Certificate Authority (CA) is responsible for:
a) Issuing and revoking digital certificates
b) Storing all private keys
c) Encrypting all data
d) Managing network traffic
Answer: a
32. Key rotation is important because:
a) It reduces the impact of a compromised key
b) It increases key size automatically
c) It is required only once
d) It has no security benefit
Answer: a
33. Common attack vectors against cloud storage include:
a) Publicly accessible buckets and weak access controls
b) Only physical access
c) Only power failure
d) Only software updates
Answer: a
34. Network security groups in cloud typically control:
a) Inbound and outbound traffic at the instance or subnet level
b) Only physical switch configuration
c) Only DNS resolution
d) Only application code
Answer: a
35. Secure isolation strategies help mitigate:
a) Cross-tenant data leakage and attacks
b) Only performance issues
c) Only cost overruns
d) Only compliance reporting
Answer: a
36. Measured boot and verified boot help ensure:
a) The boot process has not been tampered with
b) Faster boot times
c) Higher CPU usage
d) Automatic updates
Answer: a
37. Data protection strategies should include classification of data based on:
a) Sensitivity and regulatory requirements
b) Only file size
c) Only creation date
d) Only owner name
Answer: a
38. Archiving procedures for tenant data should ensure:
a) Data remains accessible according to retention policy and is protected
b) Immediate permanent deletion
c) Public accessibility
d) No encryption
Answer: a
39. Symmetric encryption is generally preferred for:
a) Encrypting large volumes of data because it is faster
b) Key exchange only
c) Digital signatures only
d) Certificate issuance
Answer: a
40. Asymmetric encryption is commonly used for:
a) Secure key exchange and digital signatures
b) Encrypting terabytes of data at rest
c) Compressing data
d) Network routing
Answer: a
41. Data redaction is often applied to:
a) Logs, reports, and documents containing PII or sensitive fields
b) Only encrypted files
c) Only network packets
d) Only virtual machine images
Answer: a
42. A token vault is used in tokenization systems to:
a) Securely store the mapping between tokens and original sensitive data
b) Store only public keys
c) Store only network configurations
d) Store only application code
Answer: a
43. Code obfuscation aims to:
a) Make reverse engineering of software more difficult
b) Improve performance
c) Reduce code size only
d) Enable open-source sharing
Answer: a
44. Hardware Security Modules (HSMs) are used in key management to:
a) Provide tamper-resistant storage and cryptographic operations for keys
b) Only store passwords
c) Only manage virtual networks
d) Only monitor traffic
Answer: a
45. In cloud environments, the principle of “least privilege” means:
a) Users and services are granted only the minimum permissions necessary
b) Everyone has administrator access
c) Permissions are never reviewed
d) All services run as root
Answer: a
46. A common threat related to virtualization is:
a) Hypervisor escape / VM breakout
b) Only slow disk I/O
c) Only high latency
d) Only licensing costs
Answer: a
47. Inter-tenant isolation can be strengthened by:
a) Using dedicated hosts or strict network policies
b) Sharing the same security groups across tenants
c) Disabling encryption
d) Allowing unrestricted east-west traffic
Answer: a
48. Secure deletion of data in cloud often relies on:
a) Cryptographic erasure (destroying keys) when physical overwrite is not possible
b) Simply marking files as deleted
c) Moving files to trash
d) Changing file permissions only
Answer: a
49. Format-preserving encryption is a form of:
a) Encryption that keeps the same data format (useful for databases and tokenization alternatives)
b) Compression
c) Hashing
d) Encoding only
Answer: a
50. Effective key management requires:
a) Separation of duties, access controls, audit logging, and secure key lifecycle management
b) Storing all keys in application source code
c) Sharing keys via email
d) Never backing up keys
Answer: a
Theory Questions – 20
1. Explain the shared responsibility model in cloud security. What are the typical responsibilities of the cloud provider and the customer?
Answer: In the shared responsibility model, the cloud provider is responsible for security of the cloud (physical infrastructure, hypervisor, network fabric, managed services security), while the customer is responsible for security in the cloud (data, applications, identity and access management, operating system configuration, network and firewall settings, encryption of data). The exact division depends on the service model (IaaS, PaaS, SaaS).
2. What are the fundamental security design principles that should be applied when designing cloud systems?
Answer: Key principles include defense in depth, least privilege, fail-secure defaults, complete mediation, separation of duties, economy of mechanism, open design, psychological acceptability, and continuous monitoring/auditing. These principles guide architecture so that security is built-in rather than bolted on.
3. Describe comprehensive data protection in a cloud environment.
Answer: Comprehensive data protection covers data at rest (encryption, access controls), data in transit (TLS/SSL, VPNs), and data in use (confidential computing, memory encryption). It also includes data classification, retention policies, secure deletion, and compliance with regulations.
4. Explain end-to-end access control in cloud computing.
Answer: End-to-end access control ensures that identity is verified and authorization decisions are enforced consistently from the user/application through the network, hypervisor, storage, and application layers. It typically involves strong authentication, fine-grained authorization (RBAC/ABAC), and continuous verification.
5. List and briefly explain common attack vectors and threats in cloud environments.
Answer: Common vectors include: misconfigured storage (public buckets), weak or stolen credentials, insecure APIs, side-channel attacks in multi-tenant environments, hypervisor vulnerabilities, insider threats, DDoS, and supply-chain attacks on cloud services or images.
6. How is network and storage security implemented in cloud platforms?
Answer: Network security uses Virtual Private Clouds (VPCs), subnets, security groups, network ACLs, private endpoints, and encryption in transit. Storage security uses encryption at rest, access policies, versioning, immutability (WORM), and secure deletion mechanisms.
7. What are secure isolation strategies in multi-tenant cloud environments?
Answer: Secure isolation prevents one tenant from affecting or accessing another’s resources. Strategies include hypervisor-level isolation, dedicated hosts, network segmentation (VPCs, security groups), storage isolation (separate encryption keys), and process/container isolation.
8. Discuss virtualization strategies from a security perspective.
Answer: Security-focused virtualization includes using hardened hypervisors, minimizing the Trusted Computing Base, enabling measured/verified boot, using nested virtualization carefully, applying least privilege to virtual machines, and monitoring for VM escape attempts.
9. Explain inter-tenant network segmentation strategies.
Answer: Techniques include Virtual Private Clouds, software-defined networking, micro-segmentation, private subnets, security groups, network policies (in Kubernetes), and zero-trust networking so that tenants cannot communicate unless explicitly allowed.
10. What are the key data protection strategies used in cloud computing?
Answer: Strategies include data classification, encryption (at rest and in transit), tokenization, redaction, access control, data loss prevention (DLP), secure key management, and regular auditing of data access.
11. Describe proper procedures for data retention, deletion, and archiving of tenant data.
Answer: Retention must follow legal and business policies. Deletion should use secure methods (crypto-shredding or multi-pass overwrite where possible). Archiving requires encryption, access controls, integrity protection, and clear retrieval procedures. All actions should be logged.
12. Explain different encryption techniques used for cloud data.
Answer: Symmetric (AES) for bulk data, asymmetric (RSA/ECC) for key exchange and signatures, envelope encryption (data key encrypted by master key), client-side vs server-side encryption, and format-preserving encryption when format must be retained.
13. What is data redaction and why is it important in cloud environments?
Answer: Data redaction is the removal or masking of sensitive information (PII, credentials, etc.) from documents, logs, or datasets before they are shared or stored. It reduces the risk of data leakage while allowing necessary information to remain usable.
14. Explain tokenization and how it differs from encryption.
Answer: Tokenization replaces sensitive data with non-sensitive tokens that have no mathematical relationship to the original data. The original data is stored in a secure token vault. Unlike encryption, tokens cannot be reversed without the vault, and the token can often retain the same format.
15. What is data obfuscation and where is it applied?
Answer: Obfuscation makes data or code difficult to understand or reverse-engineer while preserving functionality. It is used for protecting intellectual property in code, masking data in non-production environments, and reducing the value of data if it is leaked.
16. Describe the role of Public Key Infrastructure (PKI) in cloud security.
Answer: PKI provides a framework of policies, procedures, hardware, and software for creating, managing, distributing, and revoking digital certificates. It enables secure authentication, encryption of communications, and digital signatures in cloud environments.
17. What are the critical aspects of key management in cloud computing?
Answer: Secure key generation, storage (preferably in HSMs or KMS), distribution, rotation, revocation, and destruction. Keys must be protected with strong access controls, separation of duties, and comprehensive audit logging. Customer-managed keys and bring-your-own-key (BYOK) options are common.
18. Why is defense in depth important in cloud architecture?
Answer: Defense in depth layers multiple security controls (network, identity, data, application, monitoring) so that if one control fails, others still provide protection. This is especially critical in shared multi-tenant environments.
19. How does the principle of least privilege apply to cloud security design?
Answer: Users, services, and applications are granted only the minimum permissions required to perform their functions. This limits the blast radius of compromised credentials or vulnerabilities.
20. Explain the importance of secure isolation between tenants in a public cloud.
Answer: Without strong isolation, one tenant could potentially access another tenant’s data, exhaust shared resources (noisy neighbor), or launch attacks. Isolation at compute, network, and storage layers is fundamental to the multi-tenant cloud security model.
Analytical Questions – 10
1. A company stores sensitive customer data in a public cloud object storage service. The storage bucket was accidentally configured as public. Analyze the risks and recommend a complete set of preventive and detective controls.
Answer: Risks include mass data exposure, regulatory fines, reputation damage, and potential identity theft. Preventive controls: enforce private buckets by default, use IAM policies and bucket policies that deny public access, enable encryption, apply least-privilege access, and use infrastructure-as-code with policy checks. Detective controls: continuous configuration scanning, CloudTrail/equivalent logging of access, alerts on public ACL changes, and regular access reviews.
2. Two tenants share the same physical host in a public cloud. One tenant is compromised. Analyze possible attack paths against the other tenant and how modern isolation techniques mitigate them.
Answer: Possible paths include VM escape via hypervisor vulnerability, side-channel attacks (cache, timing), shared resource exhaustion, or misconfigured networking. Mitigation: hardware-assisted virtualization with strong isolation, dedicated hosts or confidential computing (memory encryption), micro-segmentation of networks, separate encryption keys per tenant, and continuous monitoring for anomalous behavior.
3. Design a data protection strategy for a healthcare application running in the cloud that must comply with strict privacy regulations. Include encryption, tokenization, redaction, and key management.
Answer: Classify data (PHI vs non-PHI). Use client-side or envelope encryption for data at rest and TLS 1.2+ in transit. Tokenize identifiers (patient IDs, SSNs). Redact sensitive fields in logs and reports. Store keys in a cloud KMS or HSM with customer-managed keys, enforce key rotation, and maintain detailed audit logs of key usage and data access. Apply least-privilege IAM and enable monitoring/alerting.
4. An organization wants to implement secure deletion of tenant data when a customer leaves the service. Physical overwrite of storage is not possible because of multi-tenancy. Analyze the problem and propose a practical solution.
Answer: Physical overwrite is infeasible in multi-tenant storage. Use crypto-shredding: encrypt all tenant data with a tenant-specific key; when the tenant leaves, securely destroy the key. The ciphertext becomes permanently unrecoverable. Combine with logical deletion, retention policy enforcement, and audit logging of the deletion event.
5. Compare the security properties of encryption versus tokenization for protecting credit-card numbers in a cloud payment system. When would you choose one over the other?
Answer: Encryption produces ciphertext that can be decrypted with the key; it is reversible and format may change. Tokenization produces irreversible tokens (without the vault) that can preserve format and are often preferred for PCI-DSS scope reduction. Choose tokenization when format must be retained and the vault can be tightly controlled; choose encryption when the data needs to be decrypted for processing and strong key management is in place. Hybrid approaches are common.
6. A cloud workload is attacked via a stolen API key that had excessive permissions. Analyze how the principles of least privilege and end-to-end access control could have limited the damage, and propose architectural improvements.
Answer: Excessive permissions allowed lateral movement and data access. Least privilege would have restricted the key to only required actions. End-to-end access control (strong authentication, short-lived credentials, continuous authorization, micro-segmentation) would have limited the blast radius. Improvements: use temporary credentials (STS), IAM roles with minimal policies, attribute-based access control, network policies, and real-time anomaly detection on API usage.
7. Analyze the role of inter-tenant network segmentation in preventing lateral movement after a successful breach of one virtual machine.
Answer: Without segmentation, an attacker who compromises one VM can scan and attack other tenants’ VMs on the same network. Proper segmentation (VPCs, security groups, private subnets, zero-trust policies) ensures that even if one VM is compromised, the attacker cannot reach other tenants’ resources unless explicit, tightly controlled paths exist. This contains the breach.
8. An organization is moving from traditional data-center security to cloud. They previously relied heavily on perimeter firewalls. Analyze why this approach is insufficient in the cloud and what architectural changes are required.
Answer: Cloud environments are highly dynamic, multi-tenant, and have no fixed perimeter. Relying only on perimeter firewalls leaves internal east-west traffic and misconfigured resources exposed. Required changes: adopt zero-trust (verify explicitly, least privilege, assume breach), implement micro-segmentation, strong identity-centric controls, encryption everywhere, continuous monitoring, and infrastructure-as-code with security guardrails.
9. Evaluate the security implications of using a shared hypervisor versus dedicated hosts for a highly sensitive workload. Include isolation, performance, and cost considerations.
Answer: Shared hypervisor offers cost efficiency and elasticity but introduces risks of side-channel attacks and potential VM escape. Dedicated hosts provide stronger isolation (physical separation), reduce noisy-neighbor and side-channel risks, and may simplify compliance, at higher cost and reduced elasticity. For highly sensitive workloads, dedicated hosts or confidential computing (memory encryption) are preferred when the risk justifies the cost.
10. Design a key management strategy for a multi-tenant SaaS application that allows each tenant to use their own encryption keys (customer-managed keys). Address generation, storage, rotation, access control, and auditability.
Answer: Use a cloud KMS that supports customer-managed keys or BYOK. Each tenant’s master key is stored in the KMS with strict IAM policies so only that tenant (and authorized services) can use it. Data keys are generated via envelope encryption and cached briefly. Implement automatic or scheduled key rotation. Enforce separation of duties, detailed CloudTrail-style logging of every key operation, and regular access reviews. Provide tenants with visibility into key usage via audit reports.