
EC-CouncilCloud Security Essentials
Domain 6Objective 1
Cloud Logging and Security Monitoring CSE Practice Questions (Page 4)
Part of the Cloud Security Monitoring and Incident Response domain, which makes up ~13% of our current practice bank.
48questions here
10free pages
8concepts
Questions 16–20
- 16
A company is preparing for a PCI-DSS audit. They need to demonstrate that their cloud logging system prevents logs from being altered. What should they implement?
Select an answer first - 17
A company uses a third-party SIEM for centralized monitoring. They want to ingest VPC flow logs, CloudTrail logs, and GuardDuty findings from AWS. Which approach is the most efficient and reliable for getting these logs into the SIEM?
Select an answer first - 18
Which compliance requirement is most directly addressed by ensuring cloud logs are retained for a specified period and are accessible for audit?
Select an answer first - 19
A company is subject to multiple compliance frameworks with conflicting log retention requirements: one requires logs to be kept for 1 year, another for 7 years. They want to minimize storage costs while staying compliant. What is the best approach?
Select an answer first - 20
A company uses Google Cloud and wants to detect anomalous behavior such as a user downloading a large number of files from a storage bucket. They have enabled Cloud Audit Logs and are considering using Google Cloud's Security Command Center. Which approach would be most effective for detecting this specific behavior?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.