
EC-CouncilCertified Cloud Security Engineer
Domain 2Objective 2
Application Security in Cloud CCSE Practice Questions (Page 1)
Part of the Cloud Platform and Application Security domain, which makes up ~19% of our current practice bank.
52questions here
11free pages
10concepts
Questions 1–5
- 1
A development team deploys a microservices application on Kubernetes. Each microservice runs in its own namespace and needs to communicate with a central authentication service. The security team wants to ensure that a compromised pod cannot access other namespaces' services and that all inter-service traffic is encrypted. What is the most effective control combination?
Select an answer first - 2
Which API security measure is most effective at preventing SQL injection attacks?
Select an answer first - 3
What is the primary purpose of an IAM role in a cloud application?
Select an answer first - 4
Which application security testing method analyzes source code without executing the application?
Select an answer first - 5
A company exposes a customer-facing REST API that processes financial transactions. The security team wants to prevent attackers from enumerating valid customer IDs through the API's GET /customers/{id} endpoint. They also need to ensure that a compromised API key from one partner cannot be used to access another partner's customer data. Which combination of controls best addresses both requirements?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCSE” is a trademark of its owner, used for identification only.