
EC-CouncilCertified Cloud Security Engineer
Domain 4Objective 1
Penetration Testing in Cloud CCSE Practice Questions (Page 7)
Part of the Cloud Penetration Testing and Incident Response domain, which makes up ~20% of our current practice bank.
52questions here
11free pages
9concepts
Questions 31–35
- 31
When adapting the OWASP Testing Guide for cloud penetration testing, what additional area must be included beyond traditional web application tests?
Select an answer first - 32
A multinational company operates a hybrid cloud: a private cloud in the EU for HR data and a public cloud (Azure) in the US for customer-facing applications. The security team plans a penetration test that will involve testing the HR application in the private cloud and the public web app in Azure. The company has offices in the EU and the US. Which consideration is most critical for the test's legal and compliance posture?
Select an answer first - 33
Which cloud service model typically gives the customer the least control over the underlying infrastructure, affecting the scope of penetration testing?
Select an answer first - 34
Which standard penetration testing methodology is commonly adapted for cloud environments by emphasizing business processes and risk assessment?
Select an answer first - 35
In an IaaS model, which of the following is the customer responsible for testing?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCSE” is a trademark of its owner, used for identification only.