Skip to main content
Your progress
0 of 4 lessons complete0%
T1 / M1.1 / Operator TIER / ~10 min

Connect a cloud account: module quiz

M1.1 module quiz

Ten questions. 80% to pass (8 of 10). Open book, unlimited retakes.

Answers are collapsed under each question. Answer first, then check.


Q1

A cloud account is at permission level read_only. A user clicks Stop on a discovered EC2 instance. What happens?

A. The executor checks the account’s live level and returns a read-only error before any cloud API call
B. The instance stops; the permission level affects only discovery, never any of the actions
C. The action queues until the account is upgraded to write
D. The UI hides the button, so the case cannot arise at all

Show answer

Correct: A. Enforcement is server-side in the executor, not a UI affordance. Discovery, recommendations and schedule attachment all still work at read_only; only execution is blocked.

Q2

A permission level is changed from read_only to read_write. Running schedules pick it up:

A. On the next service restart, once config reloads
B. On the next config-stream reconnect, in real time
C. At the next 6-hour discovery cycle, not sooner
D. Only after the schedules are re-attached by hand

Show answer

Correct: B. The scheduler re-reads each account’s level on every config-stream reconnect, so an upgrade or downgrade takes effect without a restart.

Q3

Permission Visibility shows a resource type as Denied. The 6-hour periodic discovery cron will:

A. Retry it on every discovery cycle until it does eventually succeed
B. Disable the whole cloud account until reauthorised
C. Skip recently-denied providers for 24 hours to avoid repeated failing calls
D. Fall back to a different discovery method entirely

Show answer

Correct: C. A user-triggered manual refresh always retries everything including denied providers, which is why the answer to “I just granted the permission” is always “run a manual refresh” rather than “wait”.

Q4

ZopNight stores cloud credentials:

A. In the frontend session, held only for the lifetime of that one single browser tab
B. Only in memory, re-entered once per user session
C. In plaintext in the shared configuration database
D. Encrypted at rest with per-organization isolation, rotatable and revocable without downtime

Show answer

Correct: D. The four properties of the vault model are encryption at rest, per-org isolation, no-downtime rotation and no-downtime revocation.

Q5

The AWS IAM policy is described as “read-mostly” because:

A. Reads are unrestricted and writes are enumerated to a narrow set of start/stop and scoped-remediation actions
B. It contains rather more read actions than it does write actions across the whole of the policy document
C. Writes require a second, separately-issued credential
D. It is read-only in non-prod and read-write in prod

Show answer

Correct: A. The distinction that matters in a security review is that the write half is enumerated rather than broad, so the boundary is mechanical rather than a matter of trust.

Q6

WIF-based AWS connection is recommended over static keys because:

A. It is considerably faster to configure at onboarding time than the alternative
B. It supports a wider range of resource types
C. No long-lived secret is stored; the role is assumed via federated identity
D. It avoids the cross-account setup step

Show answer

Correct: C. The credential that does not exist cannot leak. That is the same reasoning behind the GCP one-click and Azure workload-identity options.

Q7

GCP one-click connect provisions:

A. A ZopNight-managed service account with roles bound for the selected permission level
B. A user account created in the customer’s own org
C. A single shared credential used across every ZopNight customer account alike
D. Nothing at all; the integration only ever reads

Show answer

Correct: A. The signed-in Google user must be able to administer the project’s IAM. A custom role, a group grant or an inherited folder binding all qualify; roles/owner is not required.

Q8

An Azure account connected at tenant scope:

A. Is a leaf node exactly like a subscription is, so it covers only the one billing boundary at all here
B. Requires a separate credential for each subscription
C. Cannot be used for discovery, only for billing rollup
D. Auto-discovers accessible subscriptions and creates a child account per subscription, with cascading operations

Show answer

Correct: D. Credential, auth-method and delete operations on the tenant parent cascade to its children, which is the part that surprises people during a rotation.

Q9

Changing an account’s credentials or auth method:

A. Requires deleting the whole cloud account and then recreating it again completely from scratch afterwards, losing all of its history
B. Resets the cost history for that account
C. Preserves resources, groups, recommendations, cost history and schedules, after verifying the new credential resolves to the same cloud identity
D. Is only possible for AWS accounts

Show answer

Correct: C. If the new credential resolves to a different identity, the request is rejected and nothing changes. An account can be re-authenticated, never silently repointed.

Q10

Permission records are cleaned up:

A. Nightly, on a scheduled sweep
B. On cloud account deletion
C. Never, once written
D. After 90 days idle

Show answer

Correct: B. They are scoped to the account, so removing the account removes them. Leaving them would produce denied entries for an account that no longer exists.


What’s next

Back to Connect a cloud account.

Start with the bill.

Foundations takes about five hours. The first lesson is nine minutes.

Open curriculum. No login. No paywall. 290 lessons across 7 courses, three publicly verifiable credentials. Read it on the train, take the exam on a Saturday, list the credential on your résumé Monday.

5h median time to finish Foundations
0 logins, paywalls, or marketing forms
open curriculum, public credential verifier
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·