Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCloud Security Essentials

Domain 8Objective 5

Cloud Security Assessment and Penetration Testing CSE Practice Questions (Page 6)

Part of the Cloud Compliance and Governance domain, which makes up ~13% of our current practice bank.

49questions here
10free pages
6concepts

Questions 26–30

  1. 26application · medium

    After completing a cloud security assessment, a consultant identified a critical vulnerability in a customer's Azure storage account that allows public access to sensitive data. The consultant also found that the customer's security team is not aware of the vulnerability. What is the most important element to include in the final report?

    Select an answer first
  2. 27application · medium

    A penetration tester is performing reconnaissance on a target AWS environment. The tester has been given the account ID and the public IP range of the VPC. The tester wants to identify the services running on the public IPs and any misconfigured security groups. Which of the following techniques is most appropriate for this phase?

    Select an answer first
  3. 28expert · hard

    A penetration test report for a cloud environment includes a finding that a Kubernetes cluster has a misconfigured RBAC policy that allows any authenticated user to create pods. The report also notes that the cluster's audit logging is not enabled. The customer wants to remediate the issue but has limited resources. What is the most critical remediation step to prioritize?

    Select an answer first
  4. 29application · medium

    A cloud security tester is assessing a Google Cloud Platform (GCP) project that uses Cloud Functions. The tester wants to identify if any Cloud Functions have overly permissive IAM policies that allow unauthenticated invocation. Which tool or technique is most appropriate?

    Select an answer first
  5. 30application · medium

    During a penetration test, a tester discovers that an AWS IAM role has a policy that allows 's3:PutObject' on a critical bucket, but the role is assumed by an EC2 instance that is publicly accessible. The tester also finds that the instance has a known vulnerability that allows remote code execution. What is the most likely attack path an attacker could use?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.