
EC-CouncilCertified SOC Analyst
Domain 6Objective 3
SOC for Cloud Environments CSA Practice Questions (Page 5)
Part of the Incident Response, Forensics and Cloud SOC domain, which makes up ~23% of our current practice bank.
50questions here
10free pages
7concepts
Questions 21–25
- 21
A SOC team is designing log collection for a cloud environment that uses both IaaS VMs and serverless functions. The team wants to minimize cost while ensuring security-relevant events are captured. Which strategy is most cost-effective?
Select an answer first - 22
A SOC team wants to automate the response to a detected cloud misconfiguration, such as a storage bucket becoming public. The team must ensure that the automation does not disrupt legitimate business operations. Which approach best balances automation and safety?
Select an answer first - 23
A SOC analyst is reviewing cloud audit logs and sees a service account that normally authenticates from a specific IP range is now authenticating from a new geographic region at 3:00 AM. The analyst also sees a large number of 'List' and 'Get' API calls to a sensitive database. Which detection technique is most appropriate to flag this activity?
Select an answer first - 24
A SOC team wants to automatically quarantine a compromised cloud VM by applying a network security group rule that blocks all inbound and outbound traffic. Which automation approach is most appropriate?
Select an answer first - 25
A SOC analyst needs to detect a potential credential-stuffing attack against a cloud web application. Which cloud-native logging source is most directly useful for this detection?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.