
EC-CouncilCloud Security Essentials
Domain 6Objective 1
Cloud Logging and Security Monitoring CSE Practice Questions (Page 9)
Part of the Cloud Security Monitoring and Incident Response domain, which makes up ~13% of our current practice bank.
48questions here
10free pages
8concepts
Questions 41–45
- 41
A company is using AWS and has enabled VPC Flow Logs, CloudTrail, and GuardDuty. They want to centralize these logs for analysis. Which service should they use to aggregate and query these logs?
Select an answer first - 42
Which log analysis approach is most effective for detecting an anomaly such as a user accessing resources at unusual hours?
Select an answer first - 43
Which type of cloud log is most useful for detecting a brute-force attack against a web application hosted in the cloud?
Select an answer first - 44
A security analyst notices that a cloud storage bucket has been accessed from an IP address that is not on the approved list. The analyst wants to determine whether the access was successful and what data was retrieved. Which combination of log sources should the analyst examine first?
Select an answer first - 45
A DevOps team is troubleshooting a security incident where an application running on a virtual machine made unexpected outbound network connections. Which log source would provide the most direct evidence of these connections?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.