A cloud administrator is reviewing the authentication and authorization mechanism implemented within the cloud environment. Upon review, the administrator discovers the sales group is part of the finance group, and the sales team members can access the financial application. Single sign-on is also implemented, which makes access much easier.
Which of the following access control rules should be changed?
A. Discretionary-based
B. Attribute-based
C. Mandatory-based
D. Role-based
A company needs to rehost its ERP system to complete a datacenter migration to the public cloud. The company has already migrated other systems and configured VPN connections.
Which of the following MOST likely needs to be analyzed before rehosting the ERP?
A. Software
B. Licensing
C. Right-sizing
D. The network
A cloud administrator would like to deploy a cloud solution to its provider using automation techniques. Which of the following must be used? (Choose two.)
A. Auto-scaling
B. Tagging
C. Playbook
D. Templates
E. Containers
F. Serverless
An organization has multiple VLANs configured to segregate the network traffic. Following is the breakdown of the network segmentation:
1.
Production traffic (10.10.0.0/24)
2.
Network backup (10.20.0.0/25)
3.
Virtual IP network (10.20.0.128/25)
The following configuration exists on the server:

The backup administrator observes that the weekly backup is failing for this server. Which of the following commands should the administrator run to identify the issue?
A. ROUTE PRINT
B. NETSTAT-A
C. IPCONFIG /ALL
D. NET SM
The security team for a large corporation is investigating a data breach. The team members are all trying to do the same tasks but are interfering with each other's work.
Which of the following did the team MOST likely forget to implement?
A. Incident type categories
B. A calling tree
C. Change management
D. Roles and responsibilities
In an IaaS platform, which of the following actions would a systems administrator take FIRST to identify the scope of an incident?
A. Conduct a memory acquisition.
B. Snapshot all volumes attached to an instance.
C. Retrieve data from a backup.
D. Perform a traffic capture.
A cloud administrator receives an email stating the following:
“Clients are receiving emails from our web application with non-encrypted links.”
The administrator notices that links generated from the web application are opening in http://. Which of the following should be configured to redirect the traffic to https://?
A. User account access
B. Programming code
C. Web server configuration
D. Load balancer setting
A cloud administrator is having difficulty correlating logs for multiple servers. Upon inspection, the administrator finds that the time-zone settings are mismatched throughout the deployment. Which of the following solutions can help maintain time synchronization between all the resources?
A. DNS
B. IPAM
C. NTP
D. SNMP
A company that performs passive vulnerability scanning at its transit VPC has detected a vulnerability related to outdated web-server software on one of its public subnets. Which of the following can the company use to verify if this is a true positive with the least effort and cost? (Select two).
A. A network-based scan
B. An agent-based scan
C. A port scan
D. A red-team exercise
E. A credentialed scan
F. A blue-team exercise
G. Unknown environment penetration testing
Users currently access SaaS email with five-character passwords that use only letters and numbers. An administrator needs to make access more secure without changing the password policy. Which of the following will provide a more secure way of accessing email at the lowest cost?
A. Change the email service provider.
B. Enable MFA with a one-time password.
C. Implement SSO for all users.
D. Institute certificate-based authentication