Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCloud Security Essentials

Domain 8Objective 5

Cloud Security Assessment and Penetration Testing CSE Practice Questions (Page 3)

Part of the Cloud Compliance and Governance domain, which makes up ~13% of our current practice bank.

49questions here
10free pages
6concepts

Questions 11–15

  1. 11application · medium

    A company is planning a security assessment of its Azure environment, which includes a production web application, a development environment, and a third-party SaaS application used for HR. The compliance team requires that the assessment identify vulnerabilities in systems that store customer personal data. The company has a limited budget and wants to prioritize the most critical areas. What should the assessment scope include?

    Select an answer first
  2. 12expert · hard

    A penetration tester is assessing a serverless application on AWS that uses API Gateway, Lambda, and DynamoDB. The tester wants to test for authorization flaws in the API Gateway endpoints. The tester has been given the API keys for the application. What is the most effective technique to test for authorization flaws?

    Select an answer first
  3. 13application · medium

    A penetration tester is performing reconnaissance on a target cloud environment. The tester wants to identify publicly accessible storage buckets and databases without triggering alerts. Which technique is most appropriate?

    Select an answer first
  4. 14application · medium

    During a cloud security assessment, a tester finds that an AWS IAM role has a policy that allows any user in the account to assume it. The role has administrative privileges. What is the most likely attack vector this misconfiguration enables?

    Select an answer first
  5. 15application · medium

    A security assessment of a cloud environment identified a misconfigured Azure Blob Storage container that allows public read access to a backup file containing hashed user passwords. The assessment team also found that the container's diagnostic logs are not enabled. What is the most appropriate remediation recommendation to include in the report?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.