Wiz Cloud Fundamentals Practice Exam Questions and Answers – Part 7/8

Practice for the Wiz Cloud Fundamentals exam with 15 exam-style practice questions, instant answer reveals, and concise explanations of every correct answer. Topics include: A CISO is looking for a consolidated view of security metrics, compliance health, and prioritization recommendations tai. Follow @CertPunch and visit certpunch.com for more certification practice exams and study content.

Prefer hands-on? Take this round as an interactive practice test — answer every question, get instant feedback, and see your score: Start the Wiz Cloud Fundamentals practice test →

What you will practice

  • A CISO is looking for a consolidated view of security metrics, compliance health, and prioritization recommen…
  • You need to create an Automation Rule that triggers an action directly within Wiz itself, such as updating an…
  • If you want to create a response action that triggers auto-remediation based on a resource tagging convention…
  • Wiz dynamically generates an external ID for resources to maintain unique identifiers across the platform. In…
  • Where can users find the list of built-in and custom Controls in the Wiz portal?
  • What is the primary method Wiz employs to analyze entitlements by looking at permissions granted to principle…

Answers and explanations

Tap a question to expand the answer and the exam reasoning. Try to commit to your own pick first.

Q1. A CISO is looking for a consolidated view of security metrics, compliance health, and prioritization recommendations tailored for their executive team. Which portal feature is best suited for presenting this information?

Answer: C. Boards (Dashboards).

Boards provide customizable dashboards that summarize security metrics and compliance health for executives. While the inventory page details raw resource data, boards aggregate this information into role-specific, high-level visuals needed for strategic decision-making.

Q2. You need to create an Automation Rule that triggers an action directly within Wiz itself, such as updating an Issue's status or due date, without relying on external integrations like Jira. What category of actions enables this functionali…

Answer: C. Automated Platform Actions

Automated Platform Actions execute internal workflows like updating issue statuses without external integrations. This keeps lifecycle management self-contained within Wiz, unlike integration-specific actions which are strictly built to interface with third-party tools.

Q3. If you want to create a response action that triggers auto-remediation based on a resource tagging convention unique to your organization, which rule type must you first create to generate the necessary Issue?

Answer: C. Custom Graph Control or Cloud Configuration Rule.

Custom Cloud Configuration Rules or Graph Controls must be created first to detect the unique tagging violation and generate an Issue. Remember that response actions rely on these generated issues, as threat detection rules focus on runtime events rather than configuration states.

Q4. Wiz dynamically generates an external ID for resources to maintain unique identifiers across the platform. In the AWS environment, where can you retrieve the unique key (Tenant ID) that serves as the basis for the sts:ExternalId value used…

Answer: C. Tenant Info > General page

The Tenant ID used for the external ID is found under the Tenant Info General page in your settings. While deployment connectors list your cloud accounts, the actual tenant identifier needed for your IAM trust policy is located in the general settings.

Q5. Where can users find the list of built-in and custom Controls in the Wiz portal?

Answer: B. Policies > Graph Controls.

The management interface for reviewing or creating controls is located under Policies, Graph Controls. For the exam, remember that Wiz separates policy creation from general inventory views, making Policies the central hub for configuring and tuning graph-based security rules.

Q6. What is the primary method Wiz employs to analyze entitlements by looking at permissions granted to principles (users, roles, service accounts)?

Answer: B. Cloud Identity and Entitlement Management (CIEM) using effective permissions analysis.

Wiz performs effective permissions analysis on IAM policies to understand the actual actions that principals can perform, which is central to Cloud Entitlements Management. Avoid confusing this with configuration auditing, as CIEM specifically focuses on identity and access.

Q7. What are Wiz Projects primarily designed to help users manage?

Answer: A. Grouping resources based on organizational units, purpose (e.g., prod/test), or business units.

Wiz Projects are used to logically subdivide the cloud estate to group resources by organizational units, purpose, or business unit for focused management and access control. They are not used for network segmentation, but rather for creating isolated logical boundaries within the Wiz tenant.

Q8. When configuring an AWS Organization-level Connector, which key IAM role in the scanned member accounts contains the Trust Relationship policy that allows Wiz to assume the role for metadata collection?

Answer: C. Wiz Access Role

The Wiz Access Role is the read-only role assumed by the Wiz backend to fetch cloud metadata, and its Trust Policy defines the required security credentials allowing Wiz to assume it. Distinguish this from the scanner role, which is specifically used during agentless workload disk scanning.

Q9. If a Threat Detection Rule (TDR) is generating excessive noise due to expected activity, what method allows a security team to refine its detection output?

Answer: B. Configure scope limitations or update matchers within the TDR configuration.

Policy fine-tuning is accomplished by editing the TDR definition, where you can configure the project scope, adjust the matcher conditions, or modify the severity to ensure it targets only genuinely malicious events. Raising the severity alone will not reduce the volume of generated alerts.

Q10. A developer plans to use the Wiz CLI for local scanning via device code flow. Which built-in Wiz role is generally recommended as the minimum required permission set for this developer?

Answer: B. Developer

The Developer role provides the exact minimum permissions needed for local CLI scanning and testing. Global Admin offers excessive standing privilege, violating least privilege principles and making it a distractor for security-conscious deployments.

Q11. What is the primary method Wiz uses to collect metadata, network rules, and security group configurations from cloud service providers (CSPs) in a standard SaaS deployment?

Answer: B. Utilizing agentless scanning via CSP APIs (Cloud Scanner).

Wiz uses agentless scanning via read-only cloud provider APIs to pull configuration metadata into the Security Graph. Runtime sensors and disk cloning are used for deeper OS or vulnerability analysis, not baseline configuration drift detection.

Q12. Which of the following is listed as a primary resource or tool available in the API & Graph Queries Overview section for developers?

Answer: B. Python SDK and Postman collections

Wiz provides a Python SDK and Postman collections to help developers interact programmatically with the API. Look for standard developer integration tools rather than native infrastructure-as-code modules or runtime tools.

Q13. What is a major limitation of using Wiz Kubernetes Deployments (Connectors) regarding network topology?

Answer: C. They are not suitable for offline or air-gapped environments, requiring network connectivity to Wiz.

Kubernetes connectors require continuous outbound internet access to communicate with the Wiz backend, making them unsuitable for air-gapped environments. Use a Wiz Broker if you need to traverse strict internal network boundaries.

Q14. Which of the following describes a valid use case for deploying a Wiz Broker?

Answer: B. Connecting the Wiz backend to an on-premises Jira instance for ticket creation.

The Wiz Broker acts as a reverse proxy to bridge the backend with internal resources like an on-premises Jira instance. It handles ticketing integrations rather than runtime threat detection or direct bucket vulnerability scanning.

Q15. A security analyst wants to confirm Wiz coverage for a specific cloud service that is currently only 'Partially covered.' Where in the Wiz portal would they find this resource listed?

Answer: B. Inventory > Technologies page.

Partially covered services are cataloged on the Inventory Technologies page to show what is detected but not fully analyzed. Settings only displays configured connectors, while the Security Graph maps fully supported resource relationships.

More Wiz Cloud Fundamentals drills and other practice exams are on @CertPunch. New rounds drop every few days at certpunch.com.

Scroll to Top