Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Cloud Security Engineer

Domain 4Objective 1

Penetration Testing in Cloud CCSE Practice Questions (Page 6)

Part of the Cloud Penetration Testing and Incident Response domain, which makes up ~20% of our current practice bank.

52questions here
11free pages
9concepts

Questions 26–30

  1. 26foundation · easy

    When recommending remediation for a misconfigured cloud storage bucket, what is the most appropriate action?

    Select an answer first
  2. 27application · medium

    A penetration tester is performing reconnaissance on a target cloud environment. The tester finds a public GitHub repository that contains a configuration file with hardcoded cloud API keys. What is the most appropriate next step?

    Select an answer first
  3. 28expert · hard

    During a cloud penetration test, a tester discovers that a Kubernetes cluster has a misconfigured Role-Based Access Control (RBAC) that allows a service account to create pods in the kube-system namespace. The tester wants to demonstrate the impact without causing damage. Which action is most appropriate?

    Select an answer first
  4. 29expert · hard

    A penetration tester is assessing a Kubernetes cluster. The tester has identified that the cluster's dashboard is exposed to the internet without authentication. The tester wants to demonstrate the impact of this misconfiguration. Which technique is most appropriate?

    Select an answer first
  5. 30expert · hard

    A security team is conducting a penetration test of a serverless application on AWS Lambda. The application uses API Gateway and DynamoDB. The team wants to test for common cloud-specific vulnerabilities. Which testing approach is most effective?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCSE” is a trademark of its owner, used for identification only.