
EC-CouncilCertified Cloud Security Engineer
Domain 2Objective 2
Application Security in Cloud CCSE Practice Questions (Page 10)
Part of the Cloud Platform and Application Security domain, which makes up ~19% of our current practice bank.
52questions here
11free pages
10concepts
Questions 46–50
- 46
What is the primary purpose of centralized logging in a cloud application?
Select an answer first - 47
A company has a public-facing API and wants to detect a potential brute-force attack on the login endpoint. They have centralized logging in place. Which log-based detection strategy is most effective for identifying this attack pattern?
Select an answer first - 48
A team is adopting a DevSecOps approach for a cloud-native application. They want to integrate security testing into their CI/CD pipeline. The application is a set of microservices that communicate over a message queue. The team wants to identify vulnerabilities in the inter-service communication logic. Which testing approach is most appropriate?
Select an answer first - 49
A team is developing a cloud-native application and wants to identify security vulnerabilities early in the development process. They have a CI/CD pipeline that builds container images and deploys to a Kubernetes cluster. The team wants to catch common coding flaws before the code is merged and also check the final container image for known vulnerabilities before deployment. Which two tools should be integrated into the pipeline?
Select an answer first - 50
A company is implementing a DevSecOps pipeline for a cloud-native application. The security team wants to ensure that security checks are automated and do not slow down the development process. The team is considering integrating SAST, DAST, and container image scanning into the CI/CD pipeline. Which approach best balances security and speed?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCSE” is a trademark of its owner, used for identification only.