Cloud Security interview questions

45 real Cloud Security questions from the Security bank, as asked in Indian campus drives and tech interviews. Every question has a verified answer and an AI-tutor explanation on placd — free to start.

1. What is Shared responsibility model?

Junior
  1. A.endpoint giving a VM its config and credentials; a common SSRF target if unprotected (mitigated by IMDSv2)
  2. B.cloud service managing identities, roles, and fine-grained permissions for resources
  3. C.virtual stateful firewall controlling inbound/outbound traffic to cloud instances
  4. D.division of security duties where the provider secures the cloud and the customer secures what is in it
Reveal the answer + AI explanation — free account

2. Which term means: "division of security duties where the provider secures the cloud and the customer secures what is in it"?

Junior
  1. A.Shared responsibility model
  2. B.Confidential computing
  3. C.CIEM
  4. D.Encryption at rest
Reveal the answer + AI explanation — free account

3. Which statement is correct?

Junior
  1. A.Shared responsibility model — endpoint giving a VM its config and credentials; a common SSRF target if unprotected (mitigated by IMDSv2)
  2. B.Shared responsibility model — encrypting data as it moves across networks, typically with TLS
  3. C.Shared responsibility model — division of security duties where the provider secures the cloud and the customer secures what is in it
  4. D.Shared responsibility model — uncontrolled proliferation of credentials across code, configs, and pipelines
Reveal the answer + AI explanation — free account

4. What is IAM (cloud)?

Junior
  1. A.cloud service managing identities, roles, and fine-grained permissions for resources
  2. B.encrypting data as it moves across networks, typically with TLS
  3. C.preconfigured, secure, multi-account baseline for deploying cloud workloads consistently
  4. D.managed service for creating, storing, and controlling cryptographic keys
Reveal the answer + AI explanation — free account

6. Which statement is correct?

Junior
  1. A.IAM (cloud) — cloud service managing identities, roles, and fine-grained permissions for resources
  2. B.IAM (cloud) — uncontrolled proliferation of credentials across code, configs, and pipelines
  3. C.IAM (cloud) — keeping traffic to a cloud service on the private network rather than the public internet
  4. D.IAM (cloud) — managed service for creating, storing, and controlling cryptographic keys
Reveal the answer + AI explanation — free account

7. What is Security group?

Junior
  1. A.managed service for creating, storing, and controlling cryptographic keys
  2. B.protecting data in use by processing it inside hardware-based trusted execution environments
  3. C.virtual stateful firewall controlling inbound/outbound traffic to cloud instances
  4. D.misconfiguration that makes object storage readable by anyone on the internet
Reveal the answer + AI explanation — free account

9. Which statement is correct?

Junior
  1. A.Security group — granting cloud permissions to a service/workload via an attached identity instead of static keys
  2. B.Security group — protecting data in use by processing it inside hardware-based trusted execution environments
  3. C.Security group — managed service for creating, storing, and controlling cryptographic keys
  4. D.Security group — virtual stateful firewall controlling inbound/outbound traffic to cloud instances
Reveal the answer + AI explanation — free account

10. What is Encryption at rest?

Junior
  1. A.encrypting stored data so it is unreadable without the key if storage is accessed
  2. B.misconfiguration that makes object storage readable by anyone on the internet
  3. C.managed service for creating, storing, and controlling cryptographic keys
  4. D.encrypting data as it moves across networks, typically with TLS
Reveal the answer + AI explanation — free account

12. Which statement is correct?

Junior
  1. A.Encryption at rest — division of security duties where the provider secures the cloud and the customer secures what is in it
  2. B.Encryption at rest — uncontrolled proliferation of credentials across code, configs, and pipelines
  3. C.Encryption at rest — encrypting stored data so it is unreadable without the key if storage is accessed
  4. D.Encryption at rest — misconfiguration that makes object storage readable by anyone on the internet
Reveal the answer + AI explanation — free account

13. What is Encryption in transit?

Junior
  1. A.granting cloud permissions to a service/workload via an attached identity instead of static keys
  2. B.protecting data in use by processing it inside hardware-based trusted execution environments
  3. C.encrypting data as it moves across networks, typically with TLS
  4. D.endpoint giving a VM its config and credentials; a common SSRF target if unprotected (mitigated by IMDSv2)
Reveal the answer + AI explanation — free account

15. Which statement is correct?

Junior
  1. A.Encryption in transit — misconfiguration that makes object storage readable by anyone on the internet
  2. B.Encryption in transit — Cloud Infrastructure Entitlement Management analyzing and right-sizing excessive cloud permissions
  3. C.Encryption in transit — granting cloud permissions to a service/workload via an attached identity instead of static keys
  4. D.Encryption in transit — encrypting data as it moves across networks, typically with TLS
Reveal the answer + AI explanation — free account

16. What is Public bucket exposure?

Junior
  1. A.tooling that continuously detects misconfigurations and compliance gaps in cloud environments
  2. B.misconfiguration that makes object storage readable by anyone on the internet
  3. C.managed service for creating, storing, and controlling cryptographic keys
  4. D.keeping traffic to a cloud service on the private network rather than the public internet
Reveal the answer + AI explanation — free account

17. Which term means: "misconfiguration that makes object storage readable by anyone on the internet"?

Junior
  1. A.Public bucket exposure
  2. B.Private endpoint
  3. C.Cloud Security Posture Management (CSPM)
  4. D.Instance metadata service (IMDS)
Reveal the answer + AI explanation — free account

18. Which statement is correct?

Junior
  1. A.Public bucket exposure — preconfigured, secure, multi-account baseline for deploying cloud workloads consistently
  2. B.Public bucket exposure — endpoint giving a VM its config and credentials; a common SSRF target if unprotected (mitigated by IMDSv2)
  3. C.Public bucket exposure — misconfiguration that makes object storage readable by anyone on the internet
  4. D.Public bucket exposure — granting cloud permissions to a service/workload via an attached identity instead of static keys
Reveal the answer + AI explanation — free account

19. What is Key Management Service (KMS)?

Mid
  1. A.managed service for creating, storing, and controlling cryptographic keys
  2. B.tooling that continuously detects misconfigurations and compliance gaps in cloud environments
  3. C.uncontrolled proliferation of credentials across code, configs, and pipelines
  4. D.virtual stateful firewall controlling inbound/outbound traffic to cloud instances
Reveal the answer + AI explanation — free account

21. Which statement is correct?

Mid
  1. A.Key Management Service (KMS) — keeping traffic to a cloud service on the private network rather than the public internet
  2. B.Key Management Service (KMS) — preconfigured, secure, multi-account baseline for deploying cloud workloads consistently
  3. C.Key Management Service (KMS) — managed service for creating, storing, and controlling cryptographic keys
  4. D.Key Management Service (KMS) — tooling that continuously detects misconfigurations and compliance gaps in cloud environments
Reveal the answer + AI explanation — free account

22. What is Instance metadata service (IMDS)?

Mid
  1. A.uncontrolled proliferation of credentials across code, configs, and pipelines
  2. B.endpoint giving a VM its config and credentials; a common SSRF target if unprotected (mitigated by IMDSv2)
  3. C.Cloud Infrastructure Entitlement Management analyzing and right-sizing excessive cloud permissions
  4. D.misconfiguration that makes object storage readable by anyone on the internet
Reveal the answer + AI explanation — free account

23. Which term means: "endpoint giving a VM its config and credentials; a common SSRF target if unprotected (mitigated by IMDSv2)"?

Mid
  1. A.Workload identity
  2. B.Landing zone
  3. C.Encryption at rest
  4. D.Instance metadata service (IMDS)
Reveal the answer + AI explanation — free account

24. Which statement is correct?

Mid
  1. A.Instance metadata service (IMDS) — uncontrolled proliferation of credentials across code, configs, and pipelines
  2. B.Instance metadata service (IMDS) — granting cloud permissions to a service/workload via an attached identity instead of static keys
  3. C.Instance metadata service (IMDS) — endpoint giving a VM its config and credentials; a common SSRF target if unprotected (mitigated by IMDSv2)
  4. D.Instance metadata service (IMDS) — encrypting data as it moves across networks, typically with TLS
Reveal the answer + AI explanation — free account

25. What is Cloud Security Posture Management (CSPM)?

Mid
  1. A.tooling that continuously detects misconfigurations and compliance gaps in cloud environments
  2. B.division of security duties where the provider secures the cloud and the customer secures what is in it
  3. C.managed service for creating, storing, and controlling cryptographic keys
  4. D.keeping traffic to a cloud service on the private network rather than the public internet
Reveal the answer + AI explanation — free account

26. Which term means: "tooling that continuously detects misconfigurations and compliance gaps in cloud environments"?

Mid
  1. A.IAM (cloud)
  2. B.Shared responsibility model
  3. C.Cloud Security Posture Management (CSPM)
  4. D.Public bucket exposure
Reveal the answer + AI explanation — free account

27. Which statement is correct?

Mid
  1. A.Cloud Security Posture Management (CSPM) — tooling that continuously detects misconfigurations and compliance gaps in cloud environments
  2. B.Cloud Security Posture Management (CSPM) — keeping traffic to a cloud service on the private network rather than the public internet
  3. C.Cloud Security Posture Management (CSPM) — misconfiguration that makes object storage readable by anyone on the internet
  4. D.Cloud Security Posture Management (CSPM) — Cloud Infrastructure Entitlement Management analyzing and right-sizing excessive cloud permissions
Reveal the answer + AI explanation — free account

28. What is Workload identity?

Mid
  1. A.encrypting data as it moves across networks, typically with TLS
  2. B.protecting data in use by processing it inside hardware-based trusted execution environments
  3. C.misconfiguration that makes object storage readable by anyone on the internet
  4. D.granting cloud permissions to a service/workload via an attached identity instead of static keys
Reveal the answer + AI explanation — free account

30. Which statement is correct?

Mid
  1. A.Workload identity — encrypting stored data so it is unreadable without the key if storage is accessed
  2. B.Workload identity — granting cloud permissions to a service/workload via an attached identity instead of static keys
  3. C.Workload identity — preconfigured, secure, multi-account baseline for deploying cloud workloads consistently
  4. D.Workload identity — virtual stateful firewall controlling inbound/outbound traffic to cloud instances
Reveal the answer + AI explanation — free account

Showing 30 of 45 Cloud Security questions — the full set, with answers, explanations and an AI tutor on every question, is inside.

Free to start

Answers, AI explanations, and a scored voice mock interview

Sign up free to check your answers with explanations, ask the AI tutor anything on any question, and take one full AI mock interview — scored like a real panel.

Practice Cloud Security free