Skip to content

312-40 Practice Questions

Prepare for 312-40 with more than an answer.

232 questions in the full set20 sample questionsUpdated Jan 26, 2026
Exam fee
$550 USD
Level
Professional
Valid for
3 years
Domains covered on the exam 11
  1. Introduction to Cloud Security8%
  2. Platform and Infrastructure Security in Cloud12%
  3. Application Security in Cloud12%
  4. Data Security in Cloud12%
  5. Security Operations in Cloud8%
  6. Penetration Testing in Cloud8%
  7. Incident Response in Cloud8%
  8. Forensic Investigation in Cloud8%
  9. Business Continuity and Disaster Recovery in Cloud8%
  10. Governance, Risk Management, and Compliance in Cloud8%
  11. Standards, Policies, and Legal Issues in Cloud8%
  1. 1

    A company is using AWS Control Tower to manage a multi-account environment. A cloud administrator needs to ensure that no user, including the root user in any member account, can disable AWS CloudTrail or modify its configuration. Which feature of Control Tower should be used to enforce this rule?

    Show answer details

    Correct answer: C

    Preventive guardrails are implemented using Service Control Policies (SCPs) which are part of AWS Organizations. They are designed to enforce policies and prevent actions that would lead to a policy violation. An SCP can be configured to deny actions like cloudtrail:StopLogging or cloudtrail:DeleteTrail for all principals in an account, including the root user, making it the correct tool for this requirement.

  2. 2

    True or False: When conducting an authorized penetration test on Microsoft Azure, testers are permitted to perform DDoS attacks on any service as long as they provide advance notification to Microsoft.

    Show answer details

    Correct answer: B

    This statement is false. Microsoft's Rules of Engagement for penetration testing explicitly prohibit any kind of Denial of Service (DoS or DDoS) tests. Performing such attacks is a violation of the terms of service and can lead to account suspension, regardless of notification.

  3. 3

    A forensic investigator is tasked with preserving the state of a compromised EC2 instance for analysis. The goal is to capture the memory and disk state with minimal disruption to the running instance, if possible, to preserve volatile data. What are the essential first steps in this process? (Select TWO).

    Show answer details

    Correct answer: B, C

    Isolating the instance is a critical first step. It contains the potential threat, prevents communication with an attacker's C2 server, and stops lateral movement, all while keeping the instance running to preserve volatile memory.

    Creating a snapshot of the EBS volume provides a forensically sound, point-in-time copy of the disk. This allows the investigator to analyze the disk contents later without altering the original evidence.

  4. 4

    A cloud security team wants to implement the ISO/IEC 27017 code of practice for information security controls for cloud services. This standard provides guidance on security aspects relevant to both cloud service providers and cloud service customers. Which of the following is a key control specific to cloud customers outlined in ISO/IEC 27017?

    Show answer details

    Correct answer: B

    ISO/IEC 27017 places emphasis on the relationship and clear communication between the provider and customer. A key customer-side control is to establish clear agreements on how security is managed, including how incidents are monitored, reported, and responded to. This ensures clarity in the shared responsibility model.

  5. 5

    A startup is building a serverless application using AWS Lambda. The functions need to access a relational database hosted in Amazon RDS within a VPC. By default, Lambda functions run outside of any VPC. To enable secure access, the architect connects the Lambda function to the VPC. After this change, developers report that the function can no longer access public AWS services like S3 and DynamoDB, causing failures. What is the cause of this issue?

    Show answer details

    Correct answer: C

    This is the correct answer. When a Lambda function is placed inside a VPC, it uses network interfaces within the specified private subnets. These subnets do not have a default route to the internet. To access public services like S3 or DynamoDB, the VPC must have a NAT Gateway (for general internet access) or specific VPC Gateway/Interface Endpoints (for private access to AWS services).

  6. 6

    A global logistics firm uses a multi-cloud strategy with applications deployed across AWS and Azure. To standardize security monitoring, they are forwarding all logs to a central SIEM. An analyst observes that Azure Activity Logs are being ingested successfully, but AWS CloudTrail logs are not appearing. The AWS environment uses multiple accounts under AWS Organizations, and logs are centrally collected in an S3 bucket in the management account. What is the MOST likely cause of this issue?

    Show answer details

    Correct answer: A

    The most probable cause is a permissions issue. When using a central S3 bucket for AWS Organizations' CloudTrail logs, the IAM role or user credentials used by the SIEM's data connector must have the necessary s3:GetObject and s3:ListBucket permissions on that specific bucket. Network ACLs are stateless and less likely to be the root cause for a service-level integration. CloudTrail is enabled by default for management events, so it's unlikely to be disabled. A misconfigured trail would affect log generation, not ingestion by an external system if logs are present in S3.

  7. 7

    A development team is building a cloud-native application on Google Cloud Platform (GCP) and needs to manage application secrets such as API keys and database credentials. A security architect wants to ensure that secrets are not hardcoded in source code and that access is tightly controlled and audited. Which TWO GCP services should be used together to meet these requirements? (Select TWO).

    Show answer details

    Correct answer: A, C

    Secret Manager is GCP's dedicated service for storing, managing, and accessing secrets. It provides versioning, automatic rotation (via Cloud Functions), and integration with other GCP services. IAM is used to define granular permissions, specifying which principals (users, service accounts) can access which secrets.

    IAM provides the authorization mechanism to control access to Secret Manager. You use IAM policies to grant roles like 'Secret Manager Secret Accessor' to specific service accounts or users, enforcing the principle of least privilege. Secret Manager relies on IAM for its access control.

  8. 8

    A healthcare startup is deploying its patient portal application in AWS. To comply with HIPAA, all data at rest must be encrypted. A cloud engineer decides to use Server-Side Encryption with AWS KMS-Managed Keys (SSE-KMS) for the S3 buckets storing patient records. True or False: Under the AWS Shared Responsibility Model, AWS is solely responsible for managing the lifecycle and rotation of these KMS keys.

    Show answer details

    Correct answer: B

    This statement is false. While AWS manages the physical security and availability of the KMS hardware, the customer is responsible for configuring the key policies (IAM), managing grants, enabling or disabling keys, and configuring automatic key rotation. For SSE-KMS, this is a shared responsibility. The customer defines the key and its access policies; AWS manages the underlying service that performs the encryption.

  9. 9

    A financial institution is migrating its on-premises data warehouse to the cloud and has chosen Azure Synapse Analytics. Due to strict regulatory requirements, the security team must ensure that data is encrypted at rest, in transit, and that network access to the Synapse workspace is restricted to a private network. Additionally, they need to prevent data exfiltration by blocking public internet access from the workspace's managed virtual network. Which combination of Azure security features provides the most comprehensive solution to meet all these requirements?

    Show answer details

    Correct answer: B

    This is the most comprehensive and secure solution. A Managed VNet isolates the workspace. Data exfiltration protection blocks outbound public internet traffic. Managed Private Endpoints secure connections to other Azure services. A Private Endpoint for the workspace itself ensures all client connections originate from the private network, satisfying all stated requirements.

  10. 10

    A retail company has deployed a large-scale e-commerce platform on AWS, using a combination of EC2 instances for the frontend, ECS containers for microservices, and RDS for the database. During a routine audit, the security team is tasked with automating the assessment of hosts for vulnerabilities and unintended network exposure. The solution must be automated, continuously assess the environment, and provide prioritized findings. Which AWS service is specifically designed for this purpose?

    Show answer details

    Correct answer: D

    Amazon Inspector is the correct service. It is an automated vulnerability management service that continuously scans AWS workloads (EC2, ECR for containers) for software vulnerabilities and unintended network exposure. It automatically discovers running workloads, scans them, and provides a prioritized list of findings.

Create an account to continue.