
EC-CouncilCertified Cloud Security Engineer
Domain 2Objective 2
Application Security in Cloud CCSE Practice Questions (Page 6)
Part of the Cloud Platform and Application Security domain, which makes up ~19% of our current practice bank.
52questions here
11free pages
10concepts
Questions 26–30
- 26
A company is deploying a new application that must comply with GDPR. The application stores personal data of EU citizens. The compliance team requires that the data be protected and that the company can demonstrate compliance. The application team wants to ensure that the application is secure and that access to personal data is controlled. Which combination of controls should be implemented?
Select an answer first - 27
A company is running a serverless application on a cloud platform. The application uses a function that reads from a cloud storage bucket and writes to a database. The security team wants to ensure that the function has only the necessary permissions to perform its tasks. Which approach should be used to configure the function's permissions?
Select an answer first - 28
Which API security control is specifically designed to prevent a single client from overwhelming an API with too many requests?
Select an answer first - 29
Which testing approach is most effective for identifying vulnerabilities that only appear when a cloud application is running and processing real user input?
Select an answer first - 30
A company exposes a public API that allows partners to query customer account balances. The API uses an API key for authentication. A security assessment finds that the API key is sent in the URL query string, and the API returns full account details when a partner queries with a valid key. Which two changes should be made to improve security?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCSE” is a trademark of its owner, used for identification only.