312-40 Sample Questions

312-40 Sample Questions & Answers

Free Certified Cloud Security Engineer (CCSE v2) practice questions with worked answers and explanations. See how the ExamJungle simulator prepares you — then jump into the full test.

Launch the full 312-40 simulator →

Free 312-40 Sample Questions with Answers

Real questions from the Certified Cloud Security Engineer v2 practice test — answers and explanations included. Showing 10 of 20 free samples.

  1. Question 1

    A company is designing a disaster recovery (DR) plan for a critical application running in a single AWS Region. The application uses EC2 instances, an RDS database, and S3 for storing static assets. The business requires a Recovery Time Objective (RTO) of less than 1 hour and a Recovery Point Objective (RPO) of 15 minutes. The DR strategy must be cost-effective. Which DR strategy BEST meets these requirements?

    Show answer & explanation

    Correct answer: B

    The Pilot Light strategy provides a balance between cost and recovery time. The core infrastructure is running (the 'pilot light'), and data is actively replicated (RDS read replica, S3 CRR), which supports a low RPO. In a disaster, the infrastructure can be scaled out relatively quickly (e.g., via Auto Scaling), meeting the < 1 hour RTO without the cost of a fully scaled-out warm standby environment.

  2. Question 2

    A security analyst is investigating a suspected data breach in their company's AWS environment. They believe an S3 bucket containing sensitive customer data was made public for a short period. To confirm this, the analyst needs to find evidence of PutBucketAcl API calls that changed the bucket's permissions. Which log source should the analyst investigate to find this specific information?

    Show answer & explanation

    Correct answer: C

    AWS CloudTrail is the correct source. It provides a record of actions taken by a user, role, or an AWS service. All management API calls, including PutBucketAcl, are recorded in CloudTrail logs, providing the necessary audit trail for forensic investigation of permission changes.

  3. Question 3

    A government agency is deploying a sensitive application on Azure and must comply with the NIST Risk Management Framework (RMF). The agency needs a tool to define and enforce organizational standards, assess compliance at scale, and remediate non-compliant resources. Which Azure service is designed to create, assign, and manage policies that enforce these rules over resources?

    Show answer & explanation

    Correct answer: C

    Azure Policy is the correct service. It allows you to create policies that enforce and control the properties of a resource. These policies can enforce rules for resource configuration, such as allowing only certain VM SKUs or requiring tags. It has built-in policy initiatives that map to compliance frameworks like NIST, making it the ideal tool for governance and compliance enforcement.

  4. Question 4

    A cloud security architect needs to design a secure network architecture on AWS for a multi-tier web application. The design must adhere to the principle of least privilege and defense-in-depth. Which of the following represents the BEST implementation using AWS native security controls?

    graph TD subgraph VPC subgraph PublicSubnet ELB[Elastic Load Balancer] end subgraph PrivateSubnet1 Web[Web Servers] end subgraph PrivateSubnet2 App[App Servers] end subgraph PrivateSubnet3 DB[Database] end end Internet --> ELB ELB --> Web Web --> App App --> DB
    Show answer & explanation

    Correct answer: C

    This is the ideal implementation. It uses subnetting for network segmentation and granular, stateful Security Groups to enforce the principle of least privilege. Traffic flow is strictly controlled between tiers (ELB -> Web -> App -> DB), providing strong defense-in-depth.

  5. Question 5

    A European company must ensure its use of cloud services complies with GDPR. A key requirement is ensuring that personal data of EU citizens does not leave specific geographic boundaries unless adequate data protection measures are in place. Which legal and technical concept is MOST critical for the company to address when configuring their cloud environment?

    Show answer & explanation

    Correct answer: A

    Data sovereignty is the concept that information which has been converted and stored in binary digital form is subject to the laws of the country in which it is located. For GDPR compliance, this means ensuring EU citizen data is stored and processed within designated regions (like EU regions offered by cloud providers) to comply with legal requirements about data residency and cross-border transfers.

  6. Question 6Select 3

    A security team is implementing a DevSecOps pipeline for a containerized application deployed on Azure Kubernetes Service (AKS). To prevent vulnerable images from being deployed, they need to integrate an automated scanning process. At which stage of the CI/CD pipeline should container image vulnerability scanning be performed? (Select ALL that apply).

    Show answer & explanation

    Correct answers: A, B, C

    Scanning during the build phase ('shift left') is a critical best practice. It provides the earliest possible feedback to developers, allowing them to fix vulnerabilities before the image is even stored in a registry.

    Scanning images in the registry is essential. Most registries, like ACR, have built-in scanning capabilities. This ensures that even images built outside the pipeline are checked and provides a continuous assessment for newly discovered vulnerabilities in existing images.

    Runtime scanning is another layer of defense. It can detect vulnerabilities in running containers that might have been missed, or it can identify malicious processes and activities. Services like Microsoft Defender for Containers provide this capability.

  7. Question 7

    A cloud architect is evaluating different cloud service models for hosting a new custom application. The development team wants to focus solely on writing code and managing application data, without worrying about the underlying operating system, patching, or runtime environment. Which cloud service model BEST fits this requirement?

    Show answer & explanation

    Correct answer: B

    Platform as a Service (PaaS) is the correct model. It provides a platform allowing customers to develop, run, and manage applications without the complexity of building and maintaining the infrastructure typically associated with developing and launching an app. The cloud provider manages the OS, patching, and runtime, letting developers focus on their application code and data.

  8. Question 8

    A media company stores large video files in Google Cloud Storage. To reduce costs, they have implemented a lifecycle policy to transition objects to the Archive Storage class after 365 days. A video editor now needs to access a 3-year-old video file for a retrospective project. What is the process for accessing this archived object?

    Show answer & explanation

    Correct answer: B

    Correct. Objects in Google's Archive Storage are offline and must be restored before they can be accessed. Initiating a restore operation creates a temporary, cached copy of the object that becomes available for access after a few hours. The original archived object remains.

  9. Question 9

    A SOC analyst receives an alert from Microsoft Defender for Cloud indicating that a virtual machine in Azure is communicating with a known malicious IP address associated with a command-and-control (C2) server. This is the first step in the incident response process. According to the standard incident response lifecycle, what is the IMMEDIATE next step the analyst should take?

    Show answer & explanation

    Correct answer: C

    After detection and initial analysis, the immediate priority is Containment. This involves isolating the compromised system to prevent the threat from spreading to other parts of the network. This could be done by applying a restrictive Network Security Group (NSG) or moving the VM to an isolated VNet.

  10. Question 10

    A company is using AWS Control Tower to manage a multi-account environment. A cloud administrator needs to ensure that no user, including the root user in any member account, can disable AWS CloudTrail or modify its configuration. Which feature of Control Tower should be used to enforce this rule?

    Show answer & explanation

    Correct answer: C

    Preventive guardrails are implemented using Service Control Policies (SCPs) which are part of AWS Organizations. They are designed to enforce policies and prevent actions that would lead to a policy violation. An SCP can be configured to deny actions like cloudtrail:StopLogging or cloudtrail:DeleteTrail for all principals in an account, including the root user, making it the correct tool for this requirement.

10 more sample questions — free with an ExamJungle account, plus the full 312-40 simulator with 232 exam-style questions.

Ready for the real thing?

The full 312-40 simulator has every exam-style question, timed mode, and instant scoring.

Go to the 312-40 simulator →