
EC-CouncilCertified Cloud Security Engineer
Domain 4Objective 2
Incident Response in Cloud CCSE Practice Questions (Page 9)
Part of the Cloud Penetration Testing and Incident Response domain, which makes up ~20% of our current practice bank.
57questions here
12free pages
10concepts
Questions 41–45
- 41
What is the primary purpose of a post-incident review (post-mortem) in cloud incident response?
Select an answer first - 42
A company experiences a security incident that involves a data breach in a multi-cloud environment. The incident response team has contained the incident, but the company must notify affected customers and regulatory bodies. The company operates in the EU and the US. Which factor is MOST important in determining the notification requirements?
Select an answer first - 43
A security operations team wants to automate the initial response to a suspected compromised IAM credential in AWS. They want to automatically disable the IAM user and revoke temporary credentials when a CloudTrail alert fires. Which service should they use?
Select an answer first - 44
Which of the following best describes the role of orchestration in cloud incident response automation?
Select an answer first - 45
An incident response team is responding to a security incident in a cloud environment. They need to collect evidence from a compromised virtual machine while preserving chain of custody. Which step is MOST important to maintain chain of custody?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCSE” is a trademark of its owner, used for identification only.