Securing the Cloud for Implementing and Operating Cisco Security Core Technologies (SCOR 350-701)
This page covers the Securing the Cloud domain of the Implementing and Operating Cisco Security Core Technologies (SCOR 350-701) certification. Master Cybersecurity offers 26 practice questions in this domain, drawn from the same content we use across our timed exam simulations. Below are five sample questions with full answer explanations.
Sample Practice Questions
Question 1
DRAG DROP - Drag and drop the suspicious patterns for the Cisco Tetration platform from the left onto the correct definitions on the right. Select and Place:Explanation
See the answer key in the diagram.

Question 2
Which suspicious pattern enables the Cisco Tetration platform to learn the normal behavior of users?- A. file access from a different user
- B. user login suspicious behavior
- C. privilege escalation
- D. interesting file access
Explanation
The correct answer is: A. file access from a different user.
Cisco Secure Workload, formerly Tetration, installs software agents on workloads and uses them to build a baseline of what normal looks like, and file access from a different user is the pattern that makes that learning possible. The platform records which identity habitually touches which files and directories on each server, so a read or write by an account outside that learned set is a measurable deviation from the individual user's own history rather than a match against a static rule. The suspicious login pattern keys on session properties such as unusual times or sources, which is evaluated per session and does not build the per-user file profile the question is after. Privilege escalation is a condition-based detection that fires when a process ends up with rights higher than the ones it started with, independent of any behavioral baseline. Interesting file access relies on the administrator declaring sensitive paths up front, so it reflects human-defined policy instead of learned behavior.
Question 3
Which deployment model is the most secure when considering risks to cloud adoption?- A. public cloud
- B. hybrid cloud
- C. community cloud
- D. private cloud
Explanation
The correct answer is: D. private cloud.
A private cloud gives the single consuming organization dedicated infrastructure, so it is the deployment model that carries the least residual risk when adopting cloud. There is no multi-tenancy with unknown neighbors, the organization keeps direct control over the hypervisor layer, the network design, key management, patch cadence, and physical or contractual custody of the hardware, and data residency is whatever the organization decides. The trade-off is cost and elasticity, not security. A public cloud is shared by unrelated tenants over the internet, which maximizes scale and minimizes control and is where concerns about isolation, shared responsibility gaps, and misconfigured exposure are highest. A community cloud narrows the tenant pool to organizations with common requirements, such as agencies under one regulatory regime, so it is more controlled than public but still shared. A hybrid cloud stitches private and public together and therefore inherits the exposure of its public component plus the risk of the interconnect between them.
Question 4
What does the Cloudlock Apps Firewall do to mitigate security concerns from an application perspective?- A. It allows the administrator to quarantine malicious files so that the application can function, just not maliciously.
- B. It discovers and controls cloud apps that are connected to a company's corporate environment.
- C. It deletes any application that does not belong in the network.
- D. It sends the application information to an administrator to act on.
Explanation
The correct answer is: B. It discovers and controls cloud apps that are connected to a company's corporate environment..
The Cloudlock Apps Firewall addresses the third-party application risk that comes with cloud adoption: users grant OAuth tokens to external apps, and those tokens then hold standing access to corporate mail, files, and calendars without any password being shared. The Apps Firewall inventories every app connected to the organization's cloud tenants, scores each one on a community trust rating and the scopes it requested, and lets an administrator allow, block, or revoke the connection, which is exactly the discover-and-control behavior described in the correct choice. Quarantining malicious files so an application keeps working describes file-level malware handling, not OAuth app governance. Deleting any application that does not belong is too blunt to be real, since the tool revokes the grant rather than deleting software, and blanket removal would break sanctioned integrations. Merely notifying an administrator describes reporting without enforcement, and the value of the Apps Firewall is that revocation happens from the policy itself.
Question 5
Which technology reduces data loss by identifying sensitive information stored in public computing environments?- A. Cisco SDA
- B. Cisco Firepower
- C. Cisco HyperFlex
- D. Cisco Cloudlock
Explanation
The correct answer is: D. Cisco Cloudlock.
Cisco Cloudlock is the technology aimed at sensitive data that already resides in public computing environments. Working through the APIs of SaaS and IaaS platforms rather than inline, it inventories and scans stored objects, matches them against data loss prevention policies for regulated content, and then acts on what it finds by revoking public share links, alerting the owner, encrypting, or quarantining, which is how it reduces the chance of exposure. Cisco SDA, Software-Defined Access, is a campus network architecture that builds identity-based segmentation and automated fabric provisioning on the enterprise LAN, so it never inspects cloud-resident content. Cisco Firepower, now the Secure Firewall family, inspects traffic passing through it and can apply file and DLP-style controls in flight, but it cannot see data sitting at rest in a cloud tenant. Cisco HyperFlex is hyperconverged compute and storage infrastructure, a platform for running workloads rather than a data protection control.
Other Implementing and Operating Cisco Security Core Technologies (SCOR 350-701) domains
- Content Security (38 questions)
- Endpoint Protection and Detection (13 questions)
- Network Security (60 questions)
- Secure Network Access, Visibility, and Enforcement (41 questions)
- Security Concepts (102 questions)