Practice for the Wiz Cloud Fundamentals exam with 15 exam-style practice questions, instant answer reveals, and concise explanations of every correct answer. Topics include: According to the default data retention policy in Wiz, how long are resolved Wiz Issues retained in the portal after res. Follow @CertPunch and visit certpunch.com for more certification practice exams and study content.
Prefer hands-on? Take this round as an interactive practice test — answer every question, get instant feedback, and see your score: Start the Wiz Cloud Fundamentals practice test →
What you will practice
- According to the default data retention policy in Wiz, how long are resolved Wiz Issues retained in the porta…
- Which Wiz feature is primarily responsible for identifying and modeling external-facing resources like public…
- In the standard Wiz SaaS deployment model, what type of data is the Wiz backend designed to permanently store?
- How does Wiz identify and uncover security risks associated with the Linux kernel version running on a virtua…
- Which statement accurately describes the resource requirements for a Wiz Broker deployment in a customer envi…
- What is the primary source of information utilized by the Wiz Network Analyzer to calculate the 'effective ex…
Answers and explanations
Tap a question to expand the answer and the exam reasoning. Try to commit to your own pick first.
Q1. According to the default data retention policy in Wiz, how long are resolved Wiz Issues retained in the portal after resolution?
Answer: D. 180 days.
Resolved Wiz Issues are retained for 180 days after resolution by default. Memorize the standard data retention timelines for Wiz Issues, as these lifecycles frequently appear on the certification exam.
Q2. Which Wiz feature is primarily responsible for identifying and modeling external-facing resources like public websites or partner-facing services?
Answer: B. The Network Analyzer, which calculates the effective exposure based on cloud service provider (CSP) network information.
The Network Analyzer builds a model of the network architecture and calculates the effective exposure of public-facing resources using information gathered directly from the cloud service provider. The Dynamic Scanner verifies exposure paths but does not model them initially.
Q3. In the standard Wiz SaaS deployment model, what type of data is the Wiz backend designed to permanently store?
Answer: C. Metadata, such as resource identifiers and security findings (redacted where necessary).
The Wiz backend is designed only to store metadata and security findings, with sensitive data redacted to avoid storing intact copies. Wiz does not permanently retain full copies of customer data from VM disks or databases.
Q4. How does Wiz identify and uncover security risks associated with the Linux kernel version running on a virtual machine?
Answer: B. By identifying the latest installed kernel version via the OS package manager and checking the vendor's update stream.
Wiz uses the OS package manager to identify the installed kernel version and checks the vendor's update stream for associated vulnerabilities. Avoid options suggesting runtime sensors or API queries, as agentless scanning leverages existing package data and external threat intelligence.
Q5. Which statement accurately describes the resource requirements for a Wiz Broker deployment in a customer environment?
Answer: B. It has a very small resource footprint, usually not requiring more than 100 milliCPU and 128MiB of memory.
The Wiz Broker is designed to be lightweight, requiring minimal resources like one hundred milliCPU and one hundred twenty-eight mebibytes of memory. Avoid options claiming it requires heavy compute or full administrative privileges, since its primary role is secure tunneling.
Q6. What is the primary source of information utilized by the Wiz Network Analyzer to calculate the 'effective exposure' of cloud resources?
Answer: C. Information taken directly from the cloud service provider (CSP).
The Network Analyzer calculates effective exposure using configuration information retrieved directly from cloud service provider APIs. It does not rely on synthetic traffic generation or audit logs, making CSP integration essential for accurate network modeling.
Q7. A toxic combination is represented as an Issue in Wiz. Which component is responsible for identifying the findings (vulnerabilities, misconfigurations, etc.) that constitute the raw ingredients of that toxic combination?
Answer: B. Policy Rules (like CCRs and HCRs)
Policy Rules, such as Cloud Configuration Rules and Host Configuration Rules, generate the foundational findings on the Security Graph. Remember that automation rules act on existing issues, while configuration rules actually discover the raw ingredients.
Q8. If an organization needs to leverage the Wiz Model Context Protocol (MCP) Server to translate natural language queries into Wiz-specific operations via an AI assistant (like Claude Desktop), where must this feature be enabled?
Answer: A. Settings > Ask AI page (Remote MCP Server must be enabled)
The remote Model Context Protocol Server must be enabled on the Settings, Ask AI page. While the graph search bar handles typed queries, the artificial intelligence assistant integration requires activating the remote server specifically in settings.
Q9. The Wiz Runtime Sensor offers end-to-end visibility and faster response times. What type of malicious activity does it primarily focus on detecting, compared to the agentless workload scanner?
Answer: C. Known and unknown threats and malicious behaviors in real-time runtime.
The Runtime Sensor is specifically designed to detect known and unknown threats and malicious behaviors in real time. In contrast, the agentless scanner focuses on static analysis, like finding disk vulnerabilities or exposed secrets.
Q10. Which feature allows Wiz to automatically tag resources on the Security Graph (e.g., key:value pairs) based on a defined Security Graph query, which can then be used for building custom queries or Controls?
Answer: A. Resource Tag rules.
Resource Tag rules allow you to dynamically apply tags to resources based on Security Graph query results. Cloud Configuration Rules evaluate baselines, but Resource Tag rules specifically handle this dynamic graph-based tagging workflow.
Q11. In the context of the Wiz Maturity Framework, which phase is defined by achieving 100% visibility, normalizing security across cloud providers, and mapping application owners and business context?
Answer: C. Full-stack Visibility
The Full-stack Visibility phase focuses on comprehensive coverage, normalization, and context mapping. Preventive and Proactive security phases come later in the framework, focusing on shifting left and reducing risk.
Q12. A customer is mandated by regulation to ensure that third parties never have access to their VM volumes. Which Wiz deployment model is best suited to meet this requirement for workload scanning?
Answer: C. Wiz Outpost deployment
Wiz Outpost performs all workload scanning directly within the customer environment, ensuring Wiz never accesses VM volumes. The default SaaS deployment relies on snapshot sharing, which violates strict data isolation regulations.
Q13. If you are developing a custom response function for auto-remediation in GCP, what is the required language for writing the function?
Answer: A. Python
Custom response functions for Remediation and Response across all supported clouds must be written in Python. Rego is used for policy rules, and Terraform handles infrastructure provisioning, but neither builds custom automated responses.
More Wiz Cloud Fundamentals drills and other practice exams are on @CertPunch. New rounds drop every few days at certpunch.com.