Skip to main content
Your progress
0 of 4 lessons complete0%
T0 / M0.6 / Operator TIER / ~10 min

Introducing CDCR: module quiz

M0.6 module quiz

Ten questions. 80% to pass (8 of 10). Open book, unlimited retakes.

Answers are collapsed under each question. Answer first, then check.


Q1

The differentiator of CDCR against report-and-ticket is:

A. Continuous detection of waste
B. Multi-cloud support built in
C. A lower licence cost overall
D. The “act” half: closing the loop

Show answer

Correct: D. Continuous detection is table stakes across the category. The measurable difference is time-to-remediation, which is what the detect-only cost case quantifies.

Q2

“Continuous” in CDCR specifically means:

A. Real-time, sub-second detection of every single change that is made
B. Detection running on a recurring cadence rather than as a one-off audit
C. Always-on human monitoring of the estate
D. Streaming cost data rather than batched

Show answer

Correct: B. The claim is about recurrence, not latency. Anomaly detection is a daily cron, and recommendations are pre-computed rather than evaluated on request.

Q3

The cost of detect-only operation is:

A. The licence fee paid for the detection tool
B. The engineering time that is spent on running the detection
C. The savings that go unrealised while findings age in a ticket queue
D. The storage cost of retaining the findings

Show answer

Correct: C. A finding that is correct and unactioned has produced nothing. Multiplying the savings rate by the delay is what makes the detect-only case quantifiable rather than rhetorical.

Q4

Which is NOT one of CDCR’s stated boundaries?

A. It is not compatible with multi-cloud estates
B. It is not autopilot for everything
C. It is not a substitute for cost ownership
D. It is not a way to bypass change management

Show answer

Correct: A. Multi-cloud is a core capability, not a boundary. The four boundaries are about scope of automation, governance, accountability and vendor lock-in.

Q5

“Scoped write” in the read-only safety model means:

A. Writes are allowed only during a formally declared maintenance window each week
B. The credential can perform a narrow, enumerated set of mutations and nothing else
C. Writes require two separate approvals first
D. Only reads are possible, at any tier

Show answer

Correct: B. The permission is bounded by an enumerated allowlist rather than by trust. That is what makes it defensible in a security review: the boundary is mechanical.

Q6

The database denylist exists because:

A. Databases are more expensive than compute is
B. Databases simply cannot be discovered reliably enough to act on them automatically at all
C. Database mutations are frequently irreversible and the blast radius is data rather than availability
D. Providers forbid third-party database changes

Show answer

Correct: C. Losing an instance is an outage; losing data is permanent. The asymmetry is why the denylist is hardcoded rather than configurable.

Q7

CDCR being “not a way to bypass change management” means:

A. Every automated action requires its own change ticket to be raised first
B. Auto-remediation is disabled by default for all
C. Only non-production resources can be automated
D. Automation operates inside the org’s existing controls rather than around them

Show answer

Correct: D. The approval gate and the safety gate exist precisely so that automation composes with governance instead of routing around it.

Q8

Permission Visibility supports the safety model by:

A. Showing which cloud permissions were granted, denied or unknown, per resource type
B. Showing which users are able to act
C. Auditing every API call that is made
D. Restricting what the credential is actually permitted to do at runtime itself

Show answer

Correct: A. It makes the boundary observable to the customer rather than asserted by the vendor, which is the difference between a claim and evidence.

Q9

“Detect and ticket” fails primarily because:

A. Tickets are not tracked properly
B. The gap between detection and action is where savings decay
C. Detection itself is inaccurate
D. Tickets lack the technical detail that is really needed

Show answer

Correct: B. The finding is usually correct. The failure is latency, and latency is what closing the loop removes.

Q10

Which of the five things CDCR IS would be lost if the “act” half were removed?

A. Measurable time-to-remediation
B. Continuous detection coverage
C. Multi-cloud coverage breadth
D. Evidence-based findings

Show answer

Correct: A. Everything else survives detect-only. Time-to-remediation is the metric that only exists once the loop closes, which is why it is the one the category argument rests on.


What’s next

Back to Introducing CDCR.

Start with the bill.

Foundations takes about five hours. The first lesson is nine minutes.

Open curriculum. No login. No paywall. 290 lessons across 7 courses, three publicly verifiable credentials. Read it on the train, take the exam on a Saturday, list the credential on your résumé Monday.

5h median time to finish Foundations
0 logins, paywalls, or marketing forms
open curriculum, public credential verifier
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·