
EC-CouncilCertified SOC Analyst
Domain 6Objective 3
SOC for Cloud Environments CSA Practice Questions (Page 7)
Part of the Incident Response, Forensics and Cloud SOC domain, which makes up ~23% of our current practice bank.
50questions here
10free pages
7concepts
Questions 31–35
- 31
A financial institution is required to retain audit logs for seven years for compliance. The logs are stored in a cloud object storage service. The compliance team also requires that logs be immutable to prevent tampering. Which configuration best meets both requirements?
Select an answer first - 32
A SOC team wants to automate the detection and response to a specific type of attack: a user account making unusual API calls that indicate potential credential compromise. The team has a SOAR platform and access to cloud APIs. Which automation approach is most effective?
Select an answer first - 33
A SOC analyst detects that a cloud storage bucket has been made publicly readable, exposing sensitive data. Which immediate action is most appropriate?
Select an answer first - 34
A forensic investigator needs to collect evidence from a cloud VM that was involved in an incident. The VM is scheduled to be deleted in a few hours. What is the most important first step?
Select an answer first - 35
What type of cloud log records user activity, such as who accessed a resource, from which IP address, and what actions were performed?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.