
EC-CouncilCertified Cloud Security Engineer
Domain 2Objective 2
Application Security in Cloud CCSE Practice Questions (Page 2)
Part of the Cloud Platform and Application Security domain, which makes up ~19% of our current practice bank.
52questions here
11free pages
10concepts
Questions 6–10
- 6
Which security control is most directly applicable to securing container images in a cloud-native application?
Select an answer first - 7
A company's CI/CD pipeline builds a container image and pushes it to a registry. The security team wants to ensure that the image is scanned for vulnerabilities before it is deployed to production. They also want to prevent a known-vulnerable image from being deployed if it was built from a branch that is not the main branch. What is the most effective way to enforce this?
Select an answer first - 8
A security team is evaluating testing tools for a cloud application that has a complex user authentication flow. The team wants to identify vulnerabilities that require knowledge of the application's internal state, such as whether a user is logged in or has specific roles. Which testing approach is most suitable?
Select an answer first - 9
In the shared responsibility model for cloud-hosted applications, which security control is typically the responsibility of the cloud customer rather than the cloud provider?
Select an answer first - 10
A security operations team is investigating a potential breach of a cloud-hosted web application. The application logs are stored in a centralized log management service. The team needs to determine if an attacker attempted to exploit a SQL injection vulnerability in the login form. Which log data would be most useful for this investigation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCSE” is a trademark of its owner, used for identification only.