
EC-CouncilCloud Security Essentials
Domain 6Objective 1
Cloud Logging and Security Monitoring CSE Practice Questions (Page 1)
Part of the Cloud Security Monitoring and Incident Response domain, which makes up ~13% of our current practice bank.
48questions here
10free pages
8concepts
Questions 1–5
- 1
Which measure is most effective for preventing an attacker from altering logs after a security incident?
Select an answer first - 2
A security analyst is reviewing Azure Monitor logs and notices a large number of failed sign-in attempts from a single IP address across multiple users, followed by a successful sign-in for one user. Which type of attack does this pattern most likely indicate?
Select an answer first - 3
A company uses Google Cloud and wants to detect when a user creates a new Identity and Access Management (IAM) role, which is a sensitive action. Which Google Cloud service should they use to monitor this activity?
Select an answer first - 4
A security team wants to centralize logs from multiple AWS accounts into a single SIEM for monitoring. They also need to ensure that logs are not lost if the SIEM is temporarily unavailable. Which architecture best meets these requirements?
Select an answer first - 5
A security analyst is investigating a potential breach. They need to determine which user account was used to create a new virtual machine, what time it was created, and from which IP address the API call originated. Which type of cloud log should the analyst examine first?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.