
EC-CouncilCertified Cloud Security Engineer
Domain 2Objective 2
Application Security in Cloud CCSE Practice Questions (Page 8)
Part of the Cloud Platform and Application Security domain, which makes up ~19% of our current practice bank.
52questions here
11free pages
10concepts
Questions 36–40
- 36
A company runs a containerized application on a managed Kubernetes service. The security team wants to detect and respond to a compromised container that is attempting to make outbound network connections to a known command-and-control (C2) server. Which control is most effective for detecting this behavior?
Select an answer first - 37
A company is migrating a legacy on-premises application to a cloud platform. The application stores customer data and is subject to data residency requirements. The security team is reviewing the shared responsibility model. Which responsibility remains with the customer regardless of the cloud service model?
Select an answer first - 38
A development team is deploying a containerized application to a cloud platform using a CI/CD pipeline. The security team requires that all container images be scanned for vulnerabilities before deployment, and that the pipeline automatically fails if any critical vulnerability is found. The team also wants to ensure that the source code is checked for common security flaws before the build stage. Which two steps should be added to the pipeline?
Select an answer first - 39
A company stores customer data in a cloud database. The security team wants to protect the data at rest and in transit, and also ensure that only specific applications can decrypt the data. They are considering using envelope encryption. What is the primary security benefit of envelope encryption over directly encrypting data with a single key?
Select an answer first - 40
Which IAM practice helps enforce the principle of least privilege for a cloud application?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCSE” is a trademark of its owner, used for identification only.