Wiz Cloud Fundamentals Practice Exam Questions and Answers – Part 14/16

Practice for the Wiz Cloud Fundamentals exam with 15 exam-style practice questions, instant answer reveals, and concise explanations of every correct answer. Topics include: Which feature, when enabled for AWS and Azure, retrieves cost data and usage reports to establish a FinOps culture and p. Follow @CertPunch and visit certpunch.com for more certification practice exams and study content.

Prefer hands-on? Take this round as an interactive practice test — answer every question, get instant feedback, and see your score: Start the Wiz Cloud Fundamentals practice test →

What you will practice

  • Which feature, when enabled for AWS and Azure, retrieves cost data and usage reports to establish a FinOps cu…
  • Even when exposing a resource to the internet is intended (e.g., a public partner-facing website), why does W…
  • When connecting Wiz to GCP at the Organization level, which set of GCP roles must the user performing the con…
  • Wiz provides security insights to developers early in the development pipeline. Which capability detects host…
  • When scanning VMware vSphere, what type of resource is required if the vCenter API is not internet-facing?
  • What is the primary characteristic of immutable infrastructure, as adhered to by Wiz in its production enviro…

Answers and explanations

Tap a question to expand the answer and the exam reasoning. Try to commit to your own pick first.

Q1. Which feature, when enabled for AWS and Azure, retrieves cost data and usage reports to establish a FinOps culture and provide cost optimization recommendations?

Answer: B. Cloud Cost

The Cloud Cost feature provides cloud spending visibility and optimization recommendations for AWS and Azure. Remember that FinOps capabilities in Wiz are tied directly to this specific module, rather than being driven by resource tags or dynamic scanners.

Q2. Even when exposing a resource to the internet is intended (e.g., a public partner-facing website), why does Wiz consider this an inherent risk?

Answer: B. Because it combines with other signals to potentially model toxic combinations.

Public exposure is an inherent risk because Wiz combines it with other security signals to model exploitable attack paths, known as toxic combinations. Intentional exposure does not automatically violate compliance rules, but it acts as a critical multiplier.

Q3. When connecting Wiz to GCP at the Organization level, which set of GCP roles must the user performing the connection possess, in addition to being a GCP owner?

Answer: B. roles/iam.serviceAccountAdmin, roles/iam.organizationRoleAdmin, roles/iam.securityAdmin

Deploying Wiz at the GCP Organization level requires specific administrative roles for service accounts, organization roles, and security. For the exam, focus on this exact combination of IAM roles rather than general compute or storage privileges.

Q4. Wiz provides security insights to developers early in the development pipeline. Which capability detects host misconfigurations and secrets early in the SDLC?

Answer: C. Wiz CLI

The Wiz CLI shifts security left by detecting risks like host misconfigurations and secrets directly within the command line or CI/CD pipeline. Use this as your exam cue for developer integrations, contrasting it with runtime sensors for production environments.

Q5. When scanning VMware vSphere, what type of resource is required if the vCenter API is not internet-facing?

Answer: C. A Docker host with the Wiz Broker installed.

A Docker host running the Wiz Broker is required to act as a reverse proxy when the vCenter API is not internet-facing. This broker bridges the gap between your isolated vSphere environment and the Wiz backend for scanning.

Q6. What is the primary characteristic of immutable infrastructure, as adhered to by Wiz in its production environment?

Answer: B. Infrastructure lacks persistent storage, ensuring metadata is stored only in secured databases.

Immutable infrastructure means components lack persistent storage, ensuring metadata is stored only in secured, external databases. A solid exam takeaway is that this architecture prevents post-deployment modifications, directly supporting Wiz's security and data isolation model.

Q7. What type of cloud services are typically listed on the Inventory > Technologies page, often represented by a 'technology usage object' on the Security Graph, instead of a dedicated resource object?

Answer: C. Partially covered cloud services.

The correct answer is partially covered cloud services, as Wiz lists them on the Technologies page as technology usage objects. A strong distractor is fully covered services, which instead receive dedicated resource objects and full risk analysis within the Security Graph.

Q8. An experienced Wiz user needs to analyze API calls and responses generated by operations performed manually in the Wiz portal to build a custom automation script. Which tool should they use to capture these details?

Answer: C. The API Console.

The API Console is correct because it captures exact GraphQL payloads as you click through the portal, which is perfect for building custom scripts. Do not confuse this with the API Explorer, which only helps you manually write and test queries.

Q9. If a Data Finding appears in multiple files on a specific resource, how does Wiz determine the severity of the finding generated for that resource?

Answer: B. According to the maximum number of unique matches found.

The correct answer works because Wiz calculates severity based on the maximum number of unique matches across all files on that resource. Ignore options suggesting averages or severity caps; Wiz uses the highest count to reflect the true exposure accurately.

Q10. If a Cloud Connector deployment fails in AWS due to a 'Misconfigured trust relationship', which two key values must be verified in the IAM role's Trust Relationships section?

Answer: B. The Principal value (Wiz account ID) and the sts:ExternalId value (Tenant ID).

The correct answer works because the trust policy must map the Wiz account ID as the Principal and the Tenant ID as the external ID. Distractors listing policy ARNs fail because those belong in the permissions policy, not the trust relationship section.

Q11. Which license tier is required for a customer to connect Wiz to their Okta organization to scan for potential identity and secret risks, enabling a unified view of IAM?

Answer: B. Wiz Cloud Advanced or Wiz for Gov Advanced.

The correct answer works because integrating identity providers like Okta requires the higher feature thresholds found in Wiz Cloud Advanced. For the exam, associate identity and secrets scanning with advanced licensing rather than basic entry level tiers.

Q12. If you wish to create a notification when a new Wiz policy update is announced, which Automation Rule trigger type would you use?

Answer: B. Policy Update trigger: Created.

Policy Update triggers are specifically designed to notify users when changes or new policies are introduced by Wiz, allowing customers to review implementation schedules. Cloud Event triggers handle runtime occurrences, not platform policy announcements.

Q13. Which statement accurately describes the key difference in workload scanning between the standard Wiz SaaS deployment model and the Wiz Outpost deployment model?

Answer: C. In SaaS, Wiz infrastructure performs the workload scan; in Outpost, customer infrastructure performs the scan, and only security metadata results are sent to Wiz.

The primary distinction is the location where workload scanning executes. In the SaaS model, Wiz infrastructure scans the data, whereas the Outpost model executes scans within customer infrastructure, sending only security metadata back to the Wiz SaaS backend.

Q14. Wiz analyzes scanned system volumes for exposed secrets. Which type of exposed credential is a common example of a secret alert generated by Wiz?

Answer: B. Cloud platform access keys or SSH keys

Wiz detects hardcoded credentials like cloud platform access keys and SSH keys left exposed on system volumes. Customer-managed encryption keys are managed cloud services, while multi-factor authentication tokens are temporary runtime sessions.

More Wiz Cloud Fundamentals drills and other practice exams are on @CertPunch. New rounds drop every few days at certpunch.com.

Scroll to Top