
EC-CouncilCertified SOC Analyst
Domain 6Objective 3
SOC for Cloud Environments CSA Practice Questions (Page 4)
Part of the Incident Response, Forensics and Cloud SOC domain, which makes up ~23% of our current practice bank.
50questions here
10free pages
7concepts
Questions 16–20
- 16
A SOC analyst is investigating a potential account compromise in a cloud environment. The analyst sees that a user account has been used to create a new access key and then used that key to access a database. Which detection technique would most effectively identify this type of attack?
Select an answer first - 17
A company is subject to GDPR and must ensure that personal data of EU citizens is not transferred outside the EU without appropriate safeguards. The company uses a public cloud provider with regions in the EU and the US. Which approach is most compliant?
Select an answer first - 18
During a cloud incident, the SOC team must contain a compromised VM that is part of a critical application. The team has limited time and must choose between two actions: (1) isolate the VM by updating the network security group, or (2) take a snapshot of the VM before isolation. Which sequence is most appropriate?
Select an answer first - 19
A company must store customer personal data in a specific geographic region to comply with data residency regulations. Which cloud configuration is most appropriate?
Select an answer first - 20
A SOC analyst sees a series of failed login attempts to the cloud management console followed by a successful login from a new IP address. The analyst wants to detect this pattern automatically in the future. Which approach is most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.