
EC-CouncilCertified Cloud Security Engineer
Domain 2Objective 2
Application Security in Cloud CCSE Practice Questions (Page 7)
Part of the Cloud Platform and Application Security domain, which makes up ~19% of our current practice bank.
52questions here
11free pages
10concepts
Questions 31–35
- 31
A company is migrating a monolithic application to a microservices architecture on a cloud platform. Each microservice needs to access a shared database, but the security team wants to enforce least privilege so that each service can only access its own tables. The team also wants to ensure that service-to-service communication is authenticated. Which approach should be implemented?
Select an answer first - 32
Which encryption method is most appropriate for protecting data in transit between a cloud application and its users?
Select an answer first - 33
A company exposes a public REST API for its partner integrations. The security team discovers that a partner application is sending requests with a forged 'X-User-Role: admin' header, and the API gateway is trusting this header to enforce authorization. The API also lacks any request throttling, allowing a single partner to flood the endpoint. Which combination of controls should the security architect implement to address both issues?
Select an answer first - 34
Which technique is used to protect sensitive data in a cloud application by replacing it with a non-sensitive placeholder that has no reversible relationship to the original value?
Select an answer first - 35
For a serverless function, which security practice is essential to prevent unauthorized invocation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCSE” is a trademark of its owner, used for identification only.