
EC-CouncilCloud Security Essentials
Domain 6Objective 1
Cloud Logging and Security Monitoring CSE Practice Questions (Page 8)
Part of the Cloud Security Monitoring and Incident Response domain, which makes up ~13% of our current practice bank.
48questions here
10free pages
8concepts
Questions 36–40
- 36
A multinational company must comply with GDPR, which restricts the transfer of personal data outside the EU. They are designing a cloud logging architecture and need to store logs that contain personal data. What is the most appropriate approach?
Select an answer first - 37
A financial company is required to retain audit logs for seven years and must prove to auditors that the logs have not been tampered with. Which combination of measures best ensures log integrity while meeting the retention requirement?
Select an answer first - 38
A security analyst notices that a cloud storage bucket's access logs show a large number of GET requests from an IP address that is not associated with any known user or service. The analyst wants to determine if this is a legitimate data transfer or a potential data exfiltration. Which additional log source would be most helpful?
Select an answer first - 39
A security analyst is investigating a potential data exfiltration incident. They notice that a large volume of data was transferred from an S3 bucket to an external IP address. Which log source would provide the most detailed information about the data that was transferred?
Select an answer first - 40
A security analyst notices a large number of failed login attempts from a single IP address followed by a successful login. Which log analysis technique would best identify this pattern?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.