
EC-CouncilCloud Security Essentials
Domain 8Objective 5
Cloud Security Assessment and Penetration Testing CSE Practice Questions (Page 1)
Part of the Cloud Compliance and Governance domain, which makes up ~13% of our current practice bank.
49questions here
10free pages
6concepts
Questions 1–5
- 1
Which of the following is an example of an identity and access management (IAM) flaw that is a common cloud attack vector?
Select an answer first - 2
A company is planning a cloud security assessment to comply with a new industry regulation. The regulation requires that the assessment be independent and that findings be reported to the board. The company has an internal security team that is knowledgeable about the cloud environment. What is the most appropriate approach?
Select an answer first - 3
A penetration test report for a cloud environment includes a finding that an Azure VM has a public IP address and is running an outdated version of a web server with known vulnerabilities. The report also notes that the VM's network security group (NSG) allows inbound traffic from any source on port 443. The customer wants to remediate the issue but has limited budget. What is the most cost-effective remediation to prioritize?
Select an answer first - 4
Which phase of a standard penetration testing methodology involves actively probing cloud services to identify open ports and services?
Select an answer first - 5
A penetration tester is assessing a Google Cloud Platform (GCP) project. The tester needs to identify misconfigured firewall rules and overly permissive IAM roles across the project. Which approach is most effective for this assessment?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.