
EC-CouncilCertified Cloud Security Engineer
Domain 4Objective 2
Incident Response in Cloud CCSE Practice Questions (Page 11)
Part of the Cloud Penetration Testing and Incident Response domain, which makes up ~20% of our current practice bank.
57questions here
12free pages
10concepts
Questions 51–55
- 51
Which containment action is most appropriate for a compromised cloud VM that is actively communicating with a known command-and-control server?
Select an answer first - 52
A company uses AWS Organizations with multiple accounts. An alert from GuardDuty indicates that an EC2 instance in a production account is communicating with a known malicious IP. The instance has a role that allows it to access an S3 bucket containing sensitive data. The security team needs to determine if data was exfiltrated. Which approach is BEST?
Select an answer first - 53
During an incident involving a compromised Azure VM, the incident response team needs to preserve volatile evidence before shutting down the VM. The VM is running a critical application and cannot be stopped immediately. Which approach is BEST for collecting volatile evidence?
Select an answer first - 54
A security team wants to automate the response to a specific type of incident: an S3 bucket that becomes publicly readable. They want to automatically revert the bucket policy to a known good state and notify the security team. Which AWS service or feature should they use?
Select an answer first - 55
During a cloud security incident, when should the organization notify the cloud service provider (CSP)?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCSE” is a trademark of its owner, used for identification only.