Practice for the Wiz Cloud Fundamentals exam with 15 exam-style practice questions, instant answer reveals, and concise explanations of every correct answer. Topics include: In the context of the Network Analyzer, when Wiz maps the exposure path, what component is modeled as being connected to. Follow @CertPunch and visit certpunch.com for more certification practice exams and study content.
Prefer hands-on? Take this round as an interactive practice test — answer every question, get instant feedback, and see your score: Start the Wiz Cloud Fundamentals practice test →
What you will practice
- In the context of the Network Analyzer, when Wiz maps the exposure path, what component is modeled as being c…
- Which functionality allows a Wiz user to trigger internal changes to Issues and Threats within Wiz itself, wi…
- Which Wiz component is a necessary dependency for the Dynamic Scanner to perform exposure validation and eval…
- Which set of permissions is explicitly listed as highly sensitive and should almost never be included in a cu…
- Wiz identifies vulnerabilities in various OS components, including vendor platform services and packages incl…
- Where does a Wiz Administrator navigate to configure built-in host configuration assessment frameworks (like…
Answers and explanations
Tap a question to expand the answer and the exam reasoning. Try to commit to your own pick first.
Q1. In the context of the Network Analyzer, when Wiz maps the exposure path, what component is modeled as being connected to the internet?
Answer: B. Load balancers or internet gateways.
The Network Analyzer models external connection points like load balancers and internet gateways as direct links to the internet. When studying exposure paths, focus on infrastructure routing components rather than identities or vulnerability findings.
Q2. Which functionality allows a Wiz user to trigger internal changes to Issues and Threats within Wiz itself, without requiring an external integration like Jira or Slack?
Answer: B. Automated Platform Actions
Automated Platform Actions allow users to directly modify internal Wiz objects, like Issues and Threats, without external integrations. Remember that manual actions typically involve triggering external webhooks or ticketing systems like Jira.
Q3. Which Wiz component is a necessary dependency for the Dynamic Scanner to perform exposure validation and evaluation of application endpoints?
Answer: C. Network Analyzer
The Dynamic Scanner depends on the Network Analyzer to properly calculate exposure paths and validate external attack surfaces. Avoid choosing the broker or CLI, because those components handle data transmission or command-line queries instead.
Q4. Which set of permissions is explicitly listed as highly sensitive and should almost never be included in a custom user role, due to the risk of privilege escalation?
Answer: C. admin:all and create:service_accounts.
Permissions like admin:all and create:service_accounts are highly sensitive due to the severe risk of privilege escalation. For the exam, always categorize broad administrative rights as exceptions to standard custom role assignments.
Q5. Wiz identifies vulnerabilities in various OS components, including vendor platform services and packages included with the OS by default. What crucial vulnerability is specifically checked for in Linux environments to help mitigate risks i…
Answer: C. Vulnerabilities in the Linux kernel.
Wiz specifically checks the Linux kernel for vulnerabilities to mitigate risks in critical operating system components. You should easily eliminate the Windows KB option here since the question explicitly targets Linux environments.
Q6. Where does a Wiz Administrator navigate to configure built-in host configuration assessment frameworks (like OS or application hardening benchmarks)?
Answer: B. Settings > Compliance Frameworks
Built-in host configuration assessment frameworks are enabled and managed under Settings, then Compliance Frameworks, so the administrator can benchmark operating systems and applications. For the exam, remember that Inventory is for exploration, while Settings governs frameworks and rules.
Q7. Which specific action is explicitly part of the Customer Control Responsibilities when using the Wiz-managed Outpost deployment model, concerning network security?
Answer: C. Configuring firewall and port configurations in the Customer-owned cloud environment.
In the Wiz-managed Outpost model, the customer controls firewall and port configurations within their own cloud environment. Wiz handles securing the backend systems and encrypting data in transit between the Outpost and connectors.
Q8. Where can an administrator find resource discovery scripts that help estimate the number of billable units (Compute workloads, Data workloads, etc.) in their cloud environment prior to configuring the Wiz Connector?
Answer: C. The Resource Discovery Scripts documentation pages.
Resource discovery scripts are documentation tools that estimate billable usage metrics before full scanning begins. Remember that accurate counts appear on the Licenses page only after the connector successfully integrates with the environment.
Q9. What proprietary detection engine does Wiz's Malware Analyzer primarily use to identify generative malware?
Answer: A. YARA Rules written and maintained by the Wiz Research Team.
The proprietary Malware Analyzer uses YARA rules written and maintained by the Wiz Research Team to detect generative malware. While it leverages ReversingLabs for hash-based detection, the YARA engine specifically targets novel or generated threats.
Q10. Which third-party platform integrates with Wiz to pull Wiz Issues and use these insights to generate evidence around compliance controls, simplifying the audit process?
Answer: C. Scytale (Compliance Management)
Scytale is a compliance management platform that pulls Wiz issues and resources to generate evidence for compliance controls like SOC 2 and ISO 27001. Do not confuse this with DefectDojo, which focuses strictly on vulnerability management rather than audit evidence.
Q11. Wiz is designed to identify vulnerabilities in code libraries. What feature of Wiz's vulnerability scanner handles the analysis of direct and transient code library dependencies in open source libraries (SCA)?
Answer: B. Software Composition Analysis (SCA) functionality
Software Composition Analysis functionality analyzes both direct and transient code library dependencies to detect vulnerabilities in open source libraries. Expect to map dependency analysis and SCA together, distinguishing it from dynamic scanning or network analysis.
More Wiz Cloud Fundamentals drills and other practice exams are on @CertPunch. New rounds drop every few days at certpunch.com.