Cloud Security interview questions

45 Cloud Security questions from the Security bank, written for Indian campus drives and tech interviews. Every question has a verified answer and an AI-tutor explanation on placd.

Free to start: the 2-minute IT readiness check — six questions and a result.

Take the free IT readiness check

or take a mock interview set up for this area

1. What is Shared responsibility model?

Junior
  1. A.endpoint giving a VM its config and credentials; a common SSRF target if unprotected (mitigated by IMDSv2)
  2. B.cloud service managing identities, roles, and fine-grained permissions for resources
  3. C.virtual stateful firewall controlling inbound/outbound traffic to cloud instances
  4. D.division of security duties where the provider secures the cloud and the customer secures what is in it

Answer + AI explanation with Pro

2. Which term means: "division of security duties where the provider secures the cloud and the customer secures what is in it"?

Junior
  1. A.Shared responsibility model
  2. B.Confidential computing
  3. C.CIEM
  4. D.Encryption at rest

Answer + AI explanation with Pro

3. Which statement is correct?

Junior
  1. A.Shared responsibility model — endpoint giving a VM its config and credentials; a common SSRF target if unprotected (mitigated by IMDSv2)
  2. B.Shared responsibility model — encrypting data as it moves across networks, typically with TLS
  3. C.Shared responsibility model — division of security duties where the provider secures the cloud and the customer secures what is in it
  4. D.Shared responsibility model — uncontrolled proliferation of credentials across code, configs, and pipelines

Answer + AI explanation with Pro

4. What is IAM (cloud)?

Junior
  1. A.cloud service managing identities, roles, and fine-grained permissions for resources
  2. B.encrypting data as it moves across networks, typically with TLS
  3. C.preconfigured, secure, multi-account baseline for deploying cloud workloads consistently
  4. D.managed service for creating, storing, and controlling cryptographic keys

Answer + AI explanation with Pro

5. Which term means: "cloud service managing identities, roles, and fine-grained permissions for resources"?

Junior
  1. A.Workload identity
  2. B.IAM (cloud)
  3. C.CIEM
  4. D.Landing zone

Answer + AI explanation with Pro

6. Which statement is correct?

Junior
  1. A.IAM (cloud) — cloud service managing identities, roles, and fine-grained permissions for resources
  2. B.IAM (cloud) — uncontrolled proliferation of credentials across code, configs, and pipelines
  3. C.IAM (cloud) — keeping traffic to a cloud service on the private network rather than the public internet
  4. D.IAM (cloud) — managed service for creating, storing, and controlling cryptographic keys

Answer + AI explanation with Pro

7. What is Security group?

Junior
  1. A.managed service for creating, storing, and controlling cryptographic keys
  2. B.protecting data in use by processing it inside hardware-based trusted execution environments
  3. C.virtual stateful firewall controlling inbound/outbound traffic to cloud instances
  4. D.misconfiguration that makes object storage readable by anyone on the internet

Answer + AI explanation with Pro

8. Which term means: "virtual stateful firewall controlling inbound/outbound traffic to cloud instances"?

Junior
  1. A.Security group
  2. B.Workload identity
  3. C.Key Management Service (KMS)
  4. D.CIEM

Answer + AI explanation with Pro

9. Which statement is correct?

Junior
  1. A.Security group — granting cloud permissions to a service/workload via an attached identity instead of static keys
  2. B.Security group — protecting data in use by processing it inside hardware-based trusted execution environments
  3. C.Security group — managed service for creating, storing, and controlling cryptographic keys
  4. D.Security group — virtual stateful firewall controlling inbound/outbound traffic to cloud instances

Answer + AI explanation with Pro

10. What is Encryption at rest?

Junior
  1. A.encrypting stored data so it is unreadable without the key if storage is accessed
  2. B.misconfiguration that makes object storage readable by anyone on the internet
  3. C.managed service for creating, storing, and controlling cryptographic keys
  4. D.encrypting data as it moves across networks, typically with TLS

Answer + AI explanation with Pro

11. Which term means: "encrypting stored data so it is unreadable without the key if storage is accessed"?

Junior
  1. A.Encryption at rest
  2. B.Security group
  3. C.Shared responsibility model
  4. D.Secrets sprawl

Answer + AI explanation with Pro

12. Which statement is correct?

Junior
  1. A.Encryption at rest — division of security duties where the provider secures the cloud and the customer secures what is in it
  2. B.Encryption at rest — uncontrolled proliferation of credentials across code, configs, and pipelines
  3. C.Encryption at rest — encrypting stored data so it is unreadable without the key if storage is accessed
  4. D.Encryption at rest — misconfiguration that makes object storage readable by anyone on the internet

Answer + AI explanation with Pro

13. What is Encryption in transit?

Junior
  1. A.granting cloud permissions to a service/workload via an attached identity instead of static keys
  2. B.protecting data in use by processing it inside hardware-based trusted execution environments
  3. C.encrypting data as it moves across networks, typically with TLS
  4. D.endpoint giving a VM its config and credentials; a common SSRF target if unprotected (mitigated by IMDSv2)

Answer + AI explanation with Pro

14. Which term means: "encrypting data as it moves across networks, typically with TLS"?

Junior
  1. A.Secrets sprawl
  2. B.Encryption at rest
  3. C.Shared responsibility model
  4. D.Encryption in transit

Answer + AI explanation with Pro

15. Which statement is correct?

Junior
  1. A.Encryption in transit — misconfiguration that makes object storage readable by anyone on the internet
  2. B.Encryption in transit — Cloud Infrastructure Entitlement Management analyzing and right-sizing excessive cloud permissions
  3. C.Encryption in transit — granting cloud permissions to a service/workload via an attached identity instead of static keys
  4. D.Encryption in transit — encrypting data as it moves across networks, typically with TLS

Answer + AI explanation with Pro

16. What is Public bucket exposure?

Junior
  1. A.tooling that continuously detects misconfigurations and compliance gaps in cloud environments
  2. B.misconfiguration that makes object storage readable by anyone on the internet
  3. C.managed service for creating, storing, and controlling cryptographic keys
  4. D.keeping traffic to a cloud service on the private network rather than the public internet

Answer + AI explanation with Pro

17. Which term means: "misconfiguration that makes object storage readable by anyone on the internet"?

Junior
  1. A.Public bucket exposure
  2. B.Private endpoint
  3. C.Cloud Security Posture Management (CSPM)
  4. D.Instance metadata service (IMDS)

Answer + AI explanation with Pro

18. Which statement is correct?

Junior
  1. A.Public bucket exposure — preconfigured, secure, multi-account baseline for deploying cloud workloads consistently
  2. B.Public bucket exposure — endpoint giving a VM its config and credentials; a common SSRF target if unprotected (mitigated by IMDSv2)
  3. C.Public bucket exposure — misconfiguration that makes object storage readable by anyone on the internet
  4. D.Public bucket exposure — granting cloud permissions to a service/workload via an attached identity instead of static keys

Answer + AI explanation with Pro

19. What is Key Management Service (KMS)?

Mid
  1. A.managed service for creating, storing, and controlling cryptographic keys
  2. B.tooling that continuously detects misconfigurations and compliance gaps in cloud environments
  3. C.uncontrolled proliferation of credentials across code, configs, and pipelines
  4. D.virtual stateful firewall controlling inbound/outbound traffic to cloud instances

Answer + AI explanation with Pro

20. Which term means: "managed service for creating, storing, and controlling cryptographic keys"?

Mid
  1. A.Landing zone
  2. B.CIEM
  3. C.Secrets sprawl
  4. D.Key Management Service (KMS)

Answer + AI explanation with Pro

21. Which statement is correct?

Mid
  1. A.Key Management Service (KMS) — keeping traffic to a cloud service on the private network rather than the public internet
  2. B.Key Management Service (KMS) — preconfigured, secure, multi-account baseline for deploying cloud workloads consistently
  3. C.Key Management Service (KMS) — managed service for creating, storing, and controlling cryptographic keys
  4. D.Key Management Service (KMS) — tooling that continuously detects misconfigurations and compliance gaps in cloud environments

Answer + AI explanation with Pro

22. What is Instance metadata service (IMDS)?

Mid
  1. A.uncontrolled proliferation of credentials across code, configs, and pipelines
  2. B.endpoint giving a VM its config and credentials; a common SSRF target if unprotected (mitigated by IMDSv2)
  3. C.Cloud Infrastructure Entitlement Management analyzing and right-sizing excessive cloud permissions
  4. D.misconfiguration that makes object storage readable by anyone on the internet

Answer + AI explanation with Pro

23. Which term means: "endpoint giving a VM its config and credentials; a common SSRF target if unprotected (mitigated by IMDSv2)"?

Mid
  1. A.Workload identity
  2. B.Landing zone
  3. C.Encryption at rest
  4. D.Instance metadata service (IMDS)

Answer + AI explanation with Pro

24. Which statement is correct?

Mid
  1. A.Instance metadata service (IMDS) — uncontrolled proliferation of credentials across code, configs, and pipelines
  2. B.Instance metadata service (IMDS) — granting cloud permissions to a service/workload via an attached identity instead of static keys
  3. C.Instance metadata service (IMDS) — endpoint giving a VM its config and credentials; a common SSRF target if unprotected (mitigated by IMDSv2)
  4. D.Instance metadata service (IMDS) — encrypting data as it moves across networks, typically with TLS

Answer + AI explanation with Pro

25. What is Cloud Security Posture Management (CSPM)?

Mid
  1. A.tooling that continuously detects misconfigurations and compliance gaps in cloud environments
  2. B.division of security duties where the provider secures the cloud and the customer secures what is in it
  3. C.managed service for creating, storing, and controlling cryptographic keys
  4. D.keeping traffic to a cloud service on the private network rather than the public internet

Answer + AI explanation with Pro

26. Which term means: "tooling that continuously detects misconfigurations and compliance gaps in cloud environments"?

Mid
  1. A.IAM (cloud)
  2. B.Shared responsibility model
  3. C.Cloud Security Posture Management (CSPM)
  4. D.Public bucket exposure

Answer + AI explanation with Pro

27. Which statement is correct?

Mid
  1. A.Cloud Security Posture Management (CSPM) — tooling that continuously detects misconfigurations and compliance gaps in cloud environments
  2. B.Cloud Security Posture Management (CSPM) — keeping traffic to a cloud service on the private network rather than the public internet
  3. C.Cloud Security Posture Management (CSPM) — misconfiguration that makes object storage readable by anyone on the internet
  4. D.Cloud Security Posture Management (CSPM) — Cloud Infrastructure Entitlement Management analyzing and right-sizing excessive cloud permissions

Answer + AI explanation with Pro

28. What is Workload identity?

Mid
  1. A.encrypting data as it moves across networks, typically with TLS
  2. B.protecting data in use by processing it inside hardware-based trusted execution environments
  3. C.misconfiguration that makes object storage readable by anyone on the internet
  4. D.granting cloud permissions to a service/workload via an attached identity instead of static keys

Answer + AI explanation with Pro

29. Which term means: "granting cloud permissions to a service/workload via an attached identity instead of static keys"?

Mid
  1. A.CIEM
  2. B.Instance metadata service (IMDS)
  3. C.Confidential computing
  4. D.Workload identity

Answer + AI explanation with Pro

30. Which statement is correct?

Mid
  1. A.Workload identity — encrypting stored data so it is unreadable without the key if storage is accessed
  2. B.Workload identity — granting cloud permissions to a service/workload via an attached identity instead of static keys
  3. C.Workload identity — preconfigured, secure, multi-account baseline for deploying cloud workloads consistently
  4. D.Workload identity — virtual stateful firewall controlling inbound/outbound traffic to cloud instances

Answer + AI explanation with Pro

Showing 30 of 45 Cloud Security questions — the full set, with answers, explanations and an AI tutor on every question, is inside.

Free to start

Start with a free readiness check

Sign up free for the 2-minute IT readiness check and a scored result. Answers, explanations and the AI tutor on every Cloud Security question come with Pro.

Take the free IT readiness check

or take a mock interview set up for this area

24,000+ questions & coding problemsSoftware & IT16,274 questionsGovernment jobs26 examsAptitudenew questions every timeAI practice interviewwith feedback65 topics to practiseMechanical1,149 questionsGATE ME9 papersEngineering Mathematics381 questions2-minute checkfreeDSA Problems1,422Civil1,005 questionsGATE CE9 papersCS Fundamentals1,209 questionsYour scores6 skillsSystem Design25Electrical / EEE1,047 questionsGATE EE9 papersRun your codeC++ · Java · PythonLow-Level Design144Electronics & Comm.975 questionsGATE EC9 papersAI help on every questionFull-Stack6,282Chemical1,005 questionsGATE CH9 papersAI whiteboardsystem designWork abroadEurope · remote · transfersESE ME1 paperGATE practice papers2019–2026ESE CE1 paperDate alertsbefore the last dateESE EE1 paperBehavioural courseHR round practiceESE ET1 paperResume optimizerProSSC JE ME1 paperApplication trackerSSC JE CE1 paperCompany-wise prepSSC JE EE1 paperRole roadmapsRRB JE1 subjectPriced in ₹UPI · cardsISRO SC1 paperGATE CS9 papersIBPS SO IT1 paperUGC NET CS1 paperSSC CGL26 papersIBPS PO26 papersRRB NTPC26 papersSSC CHSL26 papersIBPS Clerk26 papersSBI Clerk26 papersRRB Group D26 papersSSC CPO26 papersSSC GD26 papers