
EC-CouncilCloud Security Essentials
Domain 6Objective 1
Cloud Logging and Security Monitoring CSE Practice Questions (Page 5)
Part of the Cloud Security Monitoring and Incident Response domain, which makes up ~13% of our current practice bank.
48questions here
10free pages
8concepts
Questions 21–25
- 21
A cloud security team wants to collect logs from multiple virtual machines and storage buckets into a central location for analysis. Which approach is commonly used to aggregate these logs?
Select an answer first - 22
A security team is integrating AWS CloudTrail logs into their SIEM. They notice that the SIEM is not receiving logs for some API calls, particularly those made by the root account. What is the most likely cause?
Select an answer first - 23
A company is subject to PCI-DSS and must retain audit logs for at least one year, with the first three months immediately available for analysis. They also want to minimize storage costs. Which log storage strategy best meets these requirements?
Select an answer first - 24
Which component is typically used to send cloud logs to an external SIEM system?
Select an answer first - 25
A company's SIEM is being overwhelmed by the volume of logs from their cloud environment, causing delays in alert processing. They want to reduce the log volume without losing critical security visibility. Which strategy is most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.