
EC-CouncilCertified Cloud Security Engineer
Domain 4Objective 1
Penetration Testing in Cloud CCSE Practice Questions (Page 5)
Part of the Cloud Penetration Testing and Incident Response domain, which makes up ~20% of our current practice bank.
52questions here
11free pages
9concepts
Questions 21–25
- 21
A penetration tester is following the PTES methodology for a cloud-based application. During the intelligence gathering phase, the tester identifies a public cloud storage bucket that appears to belong to the target. What is the most appropriate next step according to PTES?
Select an answer first - 22
During a cloud penetration test, a tester finds that a cloud storage bucket allows public write access. The tester has authorization to test the environment. What is the most appropriate action to demonstrate the risk without causing damage?
Select an answer first - 23
A security consultant is hired to test a SaaS application that runs on a public cloud. The contract specifies that the consultant must not perform any testing that could affect other tenants. Which testing activity is most appropriate under this constraint?
Select an answer first - 24
What is a key element of a cloud penetration testing report?
Select an answer first - 25
A company uses a hybrid cloud: a private OpenStack environment for sensitive data and a public AWS account for web applications. The security team wants to run an external penetration test against the public-facing web app and an internal test against the private cloud. Which action must the team take before starting either test?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCSE” is a trademark of its owner, used for identification only.