Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Cloud Security Engineer

Domain 4Objective 2

Incident Response in Cloud CCSE Practice Questions (Page 11)

Part of the Cloud Penetration Testing and Incident Response domain, which makes up ~20% of our current practice bank.

57questions here
12free pages
10concepts

Questions 51–55

  1. 51foundation · easy

    Which containment action is most appropriate for a compromised cloud VM that is actively communicating with a known command-and-control server?

    Select an answer first
  2. 52expert · hard

    A company uses AWS Organizations with multiple accounts. An alert from GuardDuty indicates that an EC2 instance in a production account is communicating with a known malicious IP. The instance has a role that allows it to access an S3 bucket containing sensitive data. The security team needs to determine if data was exfiltrated. Which approach is BEST?

    Select an answer first
  3. 53application · medium

    During an incident involving a compromised Azure VM, the incident response team needs to preserve volatile evidence before shutting down the VM. The VM is running a critical application and cannot be stopped immediately. Which approach is BEST for collecting volatile evidence?

    Select an answer first
  4. 54application · medium

    A security team wants to automate the response to a specific type of incident: an S3 bucket that becomes publicly readable. They want to automatically revert the bucket policy to a known good state and notify the security team. Which AWS service or feature should they use?

    Select an answer first
  5. 55foundation · easy

    During a cloud security incident, when should the organization notify the cloud service provider (CSP)?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCSE” is a trademark of its owner, used for identification only.