
EC-CouncilCertified Cloud Security Engineer
Domain 4Objective 2
Incident Response in Cloud CCSE Practice Questions (Page 7)
Part of the Cloud Penetration Testing and Incident Response domain, which makes up ~20% of our current practice bank.
57questions here
12free pages
10concepts
Questions 31–35
- 31
Which of the following is a legal or regulatory notification requirement that may apply after a cloud data breach?
Select an answer first - 32
An incident response team is collecting evidence from a compromised Azure VM. Which of the following are appropriate evidence collection methods that preserve chain of custody? (Select all that apply.)
Select an answer first - 33
A forensic investigator is responding to a security incident involving a Kubernetes cluster running in Google Kubernetes Engine (GKE). The investigator needs to collect evidence from a compromised pod without disrupting the cluster's availability. The pod is running a containerized application that stores data in an emptyDir volume. Which approach best preserves evidence while minimizing impact?
Select an answer first - 34
An organization using Azure has detected a compromised VM that is part of a domain controller for a hybrid Active Directory environment. The VM is running critical business applications that cannot be offline for more than 30 minutes. The security team needs to contain the incident while maintaining business continuity. Which containment strategy best balances these constraints?
Select an answer first - 35
An organization discovers that a developer accidentally left an AWS S3 bucket publicly readable, exposing customer data. Which cloud-specific threat vector does this represent?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCSE” is a trademark of its owner, used for identification only.