
EC-CouncilCertified Cloud Security Engineer
Domain 2Objective 2
Application Security in Cloud CCSE Practice Questions (Page 9)
Part of the Cloud Platform and Application Security domain, which makes up ~19% of our current practice bank.
52questions here
11free pages
10concepts
Questions 41–45
- 41
During which phase of the Secure Software Development Life Cycle (SDLC) is threat modeling most commonly performed?
Select an answer first - 42
A company exposes a public API that allows third-party developers to access customer data. The API uses OAuth 2.0 for authorization. The security team discovers that the API is vulnerable to a token replay attack, where a stolen access token can be used from a different IP address. The team also wants to ensure that the API can handle a sudden spike in traffic without being overwhelmed. Which combination of controls should be implemented?
Select an answer first - 43
A company uses a cloud object storage service to host static assets for a public website. The security team wants to ensure that only the website's backend service can write to the storage bucket, while anyone on the internet can read the assets. What is the most secure way to configure access?
Select an answer first - 44
What is the primary purpose of an audit trail in a cloud application?
Select an answer first - 45
A company's CI/CD pipeline builds and deploys a web application to a cloud platform. The security team wants to ensure that no secrets are accidentally committed to the source repository and that any code containing hardcoded credentials fails the build automatically. What is the most effective way to implement this control?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCSE” is a trademark of its owner, used for identification only.