Wiz Cloud Fundamentals Practice Exam Questions and Answers – Part 17/20

Practice for the Wiz Cloud Fundamentals exam with 15 exam-style practice questions, instant answer reveals, and concise explanations of every correct answer. Topics include: The analysis of system-level packages in VMware ESXi systems is performed by accessing which specific API?. Follow @CertPunch and visit certpunch.com for more certification practice exams and study content.

Prefer hands-on? Take this round as an interactive practice test — answer every question, get instant feedback, and see your score: Start the Wiz Cloud Fundamentals practice test →

What you will practice

  • When configuring an AWS Cloud Connector, which optional policy is required to retrieve cost data from AWS acc…
  • A team wishes to automate ticket creation in Jira when a new, Critical severity Issue is generated in Wiz. Wh…
  • Where can an administrator track custom framework performance over time and measure adherence criteria requir…
  • Which types of resources are included in Wiz's default Data Security Posture Management (DSPM) scanning scope…
  • Which trigger condition allows an experienced user to initiate an Automation Rule based on the timeliness of…
  • When installing the Wiz Admission Controller (Wiz AC), how frequently does the AC communicate with the Wiz ba…

Answers and explanations

Tap a question to expand the answer and the exam reasoning. Try to commit to your own pick first.

Q1. When configuring an AWS Cloud Connector, which optional policy is required to retrieve cost data from AWS accounts?

Answer: C. WizCloudCostPolicy.

The optional WizCloudCostPolicy is attached to the Wiz IAM role to fetch cost data for cloud cost visibility. The other options handle runtime protection or EKS scanning, but they do not provide the specific permissions required for cost retrieval.

Q2. A team wishes to automate ticket creation in Jira when a new, Critical severity Issue is generated in Wiz. Which feature must be configured to link the Issue creation event (trigger) to the notification action?

Answer: D. Creating an Automation Rule.

Automation Rules link triggers like issue creation to actions such as sending tickets to Jira. Action templates only define the payload, but the automation rule itself is required to execute the workflow automatically.

Q3. Where can an administrator track custom framework performance over time and measure adherence criteria required for a successful gamification program?

Answer: B. Monitored Metrics

Monitored metrics track custom framework performance over time to assess compliance and gamification success. The security graph maps relationships, but it does not provide the longitudinal reporting needed for scorecards.

Q4. Which types of resources are included in Wiz's default Data Security Posture Management (DSPM) scanning scope, targeting sensitive data caches in the cloud?

Answer: B. Virtual machine disk files, public and private buckets, and PaaS/IaaS databases.

The default scanning scope targets cloud infrastructure including virtual machine disks, buckets, and platform databases. It does not scan external SaaS applications or on-premises file servers, which require separate connectors.

Q5. Which trigger condition allows an experienced user to initiate an Automation Rule based on the timeliness of risk mitigation?

Answer: B. The Issue is due, will be due in X days, or is overdue by X days (Due trigger).

The due trigger fires an automation rule when an issue is due, upcoming, or overdue, allowing teams to manage risk timelines. Severity and status changes are valid triggers, but they do not evaluate mitigation timeliness.

Q6. When installing the Wiz Admission Controller (Wiz AC), how frequently does the AC communicate with the Wiz backend to fetch the latest admission policies (for versions 2.5.9 and above)?

Answer: C. Every 5 minutes.

Version 2.5.9 and later fetch admission policies from the backend every five minutes to maintain enforcement. This polling interval replaced older static deployment models to ensure Kubernetes clusters receive prompt updates.

Q7. To facilitate bulk creation of users in your Wiz environment, which Terraform component is specifically recommended for this task?

Answer: C. Wiz Terraform Provider

The Wiz Terraform Provider is the recommended tool for bulk user creation and management. While the CLI handles local scans and data sources query existing infrastructure, only the provider actively manages user configurations.

Q8. Where does Wiz ingest Admission Reviews generated by the Wiz Admission Controller (Wiz AC) for monitoring and analysis?

Answer: C. They are ingested as Cloud Events and viewable on the Cloud Events Explorer page.

Wiz imports Admission Reviews as Cloud Events, allowing users to analyze them using the dedicated Cloud Events Explorer. Do not confuse these with standard configuration issues; they are processed as runtime events to trigger detections and automations.

Q9. You need to enable secure, tunnelled connectivity between the Wiz backend (SaaS) and an isolated resource, such as a private on-prem version control system or a VMware vSphere vCenter API that lacks internet access. What lightweight compon…

Answer: C. Wiz Broker

The Wiz Broker functions as a reverse proxy, tunneling communication between the Wiz backend and resources located in private or on-premises networks. A practical cue is to associate the Broker with bridging isolated networks to the SaaS platform.

Q10. What happens if a vulnerability that was previously flagged is resolved, in terms of its presence on the Wiz portal?

Answer: B. The vulnerability is removed from the Wiz portal 7 days after it is resolved.

Vulnerability findings are retained in the portal for seven days after resolution before automatic removal. This retention window ensures security teams have sufficient time to verify remediation and audit historical issue data.

Q11. Regarding customer data collected during agentless scanning, what is the core principle of Wiz's backend storage design?

Answer: B. Wiz stores only security metadata and findings, avoiding storage of customer data, files, or intact secrets.

Wiz stores only security metadata and findings, ensuring that copies of customer data, files, or intact secrets are not kept in the backend. This privacy-by-design approach means Wiz never stores actual disk images or databases.

More Wiz Cloud Fundamentals drills and other practice exams are on @CertPunch. New rounds drop every few days at certpunch.com.

Scroll to Top