
EC-CouncilCloud Security Essentials
Domain 6Objective 1
Cloud Logging and Security Monitoring CSE Practice Questions (Page 6)
Part of the Cloud Security Monitoring and Incident Response domain, which makes up ~13% of our current practice bank.
48questions here
10free pages
8concepts
Questions 26–30
- 26
A security analyst is reviewing AWS CloudTrail logs and notices that an IAM user has been making API calls from two different IP addresses at the same time. What should the analyst do first?
Select an answer first - 27
A security analyst is investigating a potential brute-force attack on a cloud-based application. They have access to the application's authentication logs and the cloud provider's network flow logs. Which analysis would best confirm the attack?
Select an answer first - 28
A company is required to maintain tamper-proof logs for compliance. They are using an on-premises SIEM and want to ensure that logs cannot be altered by an attacker who compromises the SIEM. Which approach provides the strongest protection?
Select an answer first - 29
A company wants to collect logs from its cloud-based virtual machines, containerized applications, and cloud storage buckets into a single centralized logging platform. Which approach would be the most comprehensive and efficient?
Select an answer first - 30
Which AWS service is specifically designed to record API activity in an AWS account for auditing and security monitoring?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.