
EC-CouncilCertified Cloud Security Engineer
Domain 4Objective 2
Incident Response in Cloud CCSE Practice Questions (Page 4)
Part of the Cloud Penetration Testing and Incident Response domain, which makes up ~20% of our current practice bank.
57questions here
12free pages
10concepts
Questions 16–20
- 16
During an incident in Azure, a security analyst sees a suspicious sign-in from a user account that has Global Administrator privileges. The sign-in occurred from an unfamiliar IP address at 3:00 AM. The analyst needs to determine if the account is compromised and what actions the attacker took. Which sequence of actions best achieves this?
Select an answer first - 17
A company has experienced a ransomware attack on a GCP project. The incident response team has contained the affected instances. Which of the following are appropriate eradication and recovery steps? (Select all that apply.)
Select an answer first - 18
During an incident, a forensic investigator needs to collect memory from a compromised Linux VM running in AWS. The VM is in a private subnet with no direct internet access. The investigator has IAM permissions to use Systems Manager (SSM) and AWS Lambda. The organization requires that all evidence be preserved with a documented chain of custody and that the VM remain running for further analysis. Which approach best meets these requirements?
Select an answer first - 19
After a cloud incident, the incident response team is conducting a post-mortem. They found that the incident response plan did not include specific steps for handling a compromised service account in AWS. What should the team do to improve the plan?
Select an answer first - 20
Which AWS service provides a detailed audit log of API calls made within an AWS account, which is commonly used for security monitoring and incident detection?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCSE” is a trademark of its owner, used for identification only.