25 Cloud Security Interview Questions and Answers
25 cloud security interview questions across AWS, Azure and GCP, with what each one tests and what a strong answer includes, grouped by area of responsibility.
These 25 cloud security interview questions are for the person hiring: a cloud security lead, security manager or Head of Security. They cover AWS, Azure and GCP fundamentals, real incident and design scenarios, and short hands-on tasks, and each comes with what it tests and what a strong answer includes. A table further down groups them by area, from identity to governance.
Most cloud breaches come down to two things: an identity with more access than it needs, and a resource exposed by configuration. Both are easy to talk about and hard to spot in a real account, so the questions below lean on reading policies, logs and designs. For questions that apply to every cyber role, see the main list of cyber security interview questions.
Cloud security interview questions on the fundamentals
Use two or three to check the foundations. Strong candidates answer these with examples from a real account, not from a certification syllabus.
| Question | What it tests | What a strong answer includes |
|---|---|---|
| 1. What is the shared responsibility model, and where do teams most often get it wrong? | Ownership | The provider secures the cloud itself; the customer secures what they put in it: identities, configuration and data. The line moves between infrastructure, platform and software services. Teams most often wrongly assume the provider handles configuration, access or backups. |
| 2. How do identity and permissions work in AWS, Azure and GCP? | Multi-cloud identity | AWS uses IAM policies attached to users and roles, plus resource policies, with an explicit deny always winning. Azure uses Entra ID with role assignments at management group, subscription, resource group or resource scope. GCP grants roles to principals on resources, inherited down from organisation to folder to project. |
| 3. Why are long-lived access keys a risk, and what replaces them? | Credential hygiene | They leak through code, laptops and logs, and work until someone notices. Replaced by roles with temporary credentials, managed or workload identities, and OIDC federation for CI/CD pipelines. |
| 4. What does least privilege look like for a cloud workload? | Applying the principle | One role per workload, scoped to specific resources and actions, with conditions where possible, then trimmed using access analysis tools that show which permissions are never used. |
| 5. What is the difference between a security group and a network ACL in AWS? | Cloud network controls | Security groups are stateful, attach to instances or network interfaces and only allow. Network ACLs are stateless, apply to a subnet, and process allow and deny rules in order. |
| 6. Which logs would you rely on to investigate an incident in a cloud account? | Detection readiness | AWS CloudTrail (noting that data events such as S3 object access are not logged by default), VPC Flow Logs and GuardDuty. Azure Activity Log and Entra ID sign-in and audit logs. GCP Cloud Audit Logs, where most Data Access logs are off by default. Checks this before an incident, not during one. |
| 7. What is the instance metadata service, and why do attackers target it? | A classic cloud attack path | It hands credentials to code running on an instance. A server-side request forgery flaw can let an attacker steal those credentials. IMDSv2 requires a session token, which blocks most of these attacks. |
Scenario-based cloud security interview questions
This is where cloud experience shows. Listen for the order of actions, whether the candidate checks what the logs can actually prove, and whether they fix the root cause as well as the instance.
| Question | What it tests | What a strong answer includes |
|---|---|---|
| 8. A storage bucket holding customer data has been public for three weeks. What do you do? | Exposure response | Blocks public access immediately, then works out what was exposed and whether anyone accessed it, while knowing access logs may not have been enabled, which limits what can be proved. Brings in privacy and legal, since UK GDPR may require reporting to the ICO within 72 hours. Finds the root cause and adds account-wide guardrails. |
| 9. A cloud access key was committed to a public repository an hour ago. What now? | Credential leak response | Deactivates and rotates the key first, then reviews the audit logs for every call made with it, looking for new users, new keys and new compute, especially in unusual regions. |
| 10. Audit logs show a role you do not recognise launching instances in a region you never use. What is happening? | Recognising compromise | Most likely stolen credentials used for crypto-mining. Traces how the role was assumed, snapshots and stops the instances, revokes active sessions, and adds a guardrail that blocks regions the business does not use. |
| 11. A developer needs admin access to production “just for today”. How do you handle it? | Privileged access in practice | Time-limited, approved elevation to a scoped role, fully logged, and removed automatically. Never a permanent grant. |
| 12. How would you set up security guardrails across 50 AWS accounts? | Multi-account governance | AWS Organizations with service control policies, for example to stop anyone disabling CloudTrail or using unapproved regions. Central logging to a separate account, configuration rules, and a standard baseline applied to every new account. |
| 13. A scanner reports 4,000 cloud misconfigurations. Where do you start? | Prioritisation | Internet-exposed resources, sensitive data and identity issues first. Groups findings by root cause so one template fix clears hundreds, and assigns each to an owner. |
| 14. How would you secure a CI/CD pipeline that deploys to the cloud? | Delivery security | OIDC federation instead of stored keys, a least-privileged deployment role, branch protection and approvals for production, secrets in a vault, and production separated from other environments. |
| 15. An Azure subscription owner has left the company. What do you check? | Identity lifecycle | Their role assignments, any app registrations or service principals they own and the credentials on them, automation they set up, and keys they created. Reassigns ownership and removes access. |
| 16. The business wants to move a regulated workload to the cloud. What security questions do you ask? | Risk and compliance | Data classification and where it will be stored, encryption and who controls the keys, logging and retention, identity design, the provider’s certifications, and how you would exit. |
| 17. How would you spot someone escalating privileges in your cloud account? | Cloud detection | Watches for changes to policies and role assignments, new access keys for other users, and permission to pass roles to new compute. Maps these to the MITRE ATT&CK cloud matrix and alerts on them. |
Hands-on cloud security interview tasks
Short tasks to run in the interview with demo material. Reading real policies and logs for ten minutes tells you more than any certification on the CV.
| Task | What it tests | What a strong answer includes |
|---|---|---|
| 18. Here is an AWS IAM policy. What can this identity do, and what would you change? | Policy reading | Spots wildcard actions and resources, and permissions that allow privilege escalation, such as passing any role to new compute or editing its own policies. Rewrites it to the minimum. |
| 19. Here is an S3 bucket policy. Is the bucket public? | Resource policy reading | Identifies a wildcard principal with no restricting condition as public access, and checks whether account-level Block Public Access would override it. |
| 20. Here is a list of Azure role assignments. What would worry you? | Azure RBAC | Too many Owners at subscription scope, guest accounts with Contributor, and service principals with Owner rights. |
| 21. Here is a Terraform plan. Find the security issues. | Infrastructure as code review | Spots SSH or RDP open to the internet, unencrypted storage, public access settings and overly broad roles, and fixes them in the code rather than the console. |
| 22. Here are 20 CloudTrail events. What happened? | Cloud log analysis | Builds the sequence, for example a console login from a new address, a new access key, administrator rights attached, then instances launched in a new region, and calls it a compromise. |
| 23. Write a query to find AWS console sign-ins without MFA. | Querying cloud logs | A working query against CloudTrail console login events filtered on the MFA field, and a note on how to handle accounts that sign in through single sign-on. |
| 24. Here is a network diagram for a cloud application. Where are the gaps? | Cloud network design | Spots a database subnet with a route to the internet, no control on outbound traffic, management ports open, and everything in one flat network. |
| 25. Explain this finding to the product owner who has to fix it. | Communication | The risk in business terms, the specific fix, and how long it should take. No jargon, no blame. |
For task 23, one way to answer in Microsoft Sentinel, using the AWS CloudTrail connector, looks like this:
AWSCloudTrail
| where EventName == "ConsoleLogin"
| extend MFAUsed = tostring(parse_json(AdditionalEventData).MFAUsed)
| where MFAUsed == "No"
| project TimeGenerated, UserIdentityArn, SourceIpAddress, MFAUsed
Which cloud security questions for which responsibility?
Cloud security roles split differently in every company. Pick questions from the areas the person will actually own, and weight them to the clouds you run.
| Area | What it covers | Questions to use |
|---|---|---|
| Identity and access | Roles, permissions, privileged access | 2, 3, 4, 11, 15, 17, 18, 20 |
| Data and storage | Exposure, encryption, regulated data | 8, 16, 19 |
| Network | Segmentation and exposure in the cloud | 5, 24 |
| Detection and response | Cloud logs, compromise, leaked credentials | 6, 7, 9, 10, 22, 23 |
| Governance and delivery | Guardrails, pipelines, prioritisation | 1, 12, 13, 14, 21, 25 |
If the role also covers on-premises infrastructure, add from the security engineer interview questions.
What are the red flags in a cloud security interview?
- One cloud only, without saying so. Strong on AWS but presents itself as multi-cloud, and cannot describe Azure or GCP identity at all.
- Console clicking as the fix. Corrects misconfigurations by hand instead of in the code that created them.
- Trusting the defaults. Assumes logging, encryption or private access is on unless told otherwise.
- Permissions by wildcard. Reaches for broad roles to make things work and plans to tighten them later.
- No sense of identity as the perimeter. Talks about networks first, when most cloud breaches start with credentials or permissions.
Why a hands-on task beats any cloud security interview question
Anyone who has read the documentation can explain the shared responsibility model. Spotting the one permission in a long policy that turns a reader into an administrator is the job, and you only see it when someone does it in front of you.
A hands-on assessment puts the candidate in real cloud telemetry and makes them find the answer in the data.
Used before the interview, this tells you who can work in a real cloud environment. The interview then focuses on design trade-offs and the clouds you actually run.
Frequently asked questions
What questions are asked in a cloud security interview?
Expect questions on the shared responsibility model, identity and permissions, logging and network controls, followed by scenarios such as a public storage bucket or a leaked access key. Good interviews include reading a real IAM policy, audit log or infrastructure-as-code file.
Should I test cloud security candidates on AWS, Azure and GCP?
Test on the clouds you run. Each has its own identity model and logging, and strength in one does not guarantee strength in another. If the role is multi-cloud, test each one rather than assuming skills transfer.
What does a cloud security engineer do?
A cloud security engineer designs and maintains the security of an organisation’s cloud environments: identity and permissions, network controls, logging and detection, guardrails across accounts, and the security of the pipelines that deploy to them.
Are cloud certifications enough to judge a candidate?
They show the candidate has studied a provider’s services. They do not show whether they can read a real policy or spot a misconfiguration under time pressure, which is what a hands-on task tests.
How CyberHire tests cloud security engineers before the interview
CyberHire is cyber technical screening that shows you who can read an IAM policy before you book an interview. Paste a job specification that says AWS-first and you get an AWS-weighted assessment; say multi-cloud and it tests each cloud. Candidates work on real problems: IAM policy review across AWS, Azure and GCP, storage misconfiguration hunts, cloud audit log analysis and privilege escalation paths.
Every candidate is scored the same way, with integrity signals next to each score, and you see what they found and how they explained it. See how it works for cloud security hiring. If you would rather not build the assessment yourself, our team will build it with you.
Hiring a cloud security engineer?
See who can read an IAM policy before you interview anyone.
Send us the job spec. Within 48 hours we send you a hands-on assessment built around it, in your branding, free. Weighted to the clouds you actually run, and scored the same way for every candidate.