
EC-CouncilCloud Security Essentials
Domain 8Objective 5
Cloud Security Assessment and Penetration Testing CSE Practice Questions (Page 7)
Part of the Cloud Compliance and Governance domain, which makes up ~13% of our current practice bank.
49questions here
10free pages
6concepts
Questions 31–35
- 31
What is a key limitation when performing network-based penetration testing in a cloud environment?
Select an answer first - 32
A penetration testing firm is hired to test a client's cloud environment that is subject to the General Data Protection Regulation (GDPR). The test will involve processing personal data of EU citizens. The client is based in the EU, but the testing firm's servers are located in the United States. What is the most appropriate way to handle this situation?
Select an answer first - 33
A company wants to conduct a penetration test on its AWS environment, which includes EC2 instances, an RDS database, and an S3 bucket. The company's legal team is concerned about compliance with AWS's penetration testing policy. What should the company do before starting the test?
Select an answer first - 34
What is the primary purpose of the reporting phase in a cloud penetration test?
Select an answer first - 35
A security team is conducting a penetration test on a cloud environment that uses Azure Active Directory (Azure AD) for authentication. The team discovers that an application's service principal has 'Global Administrator' role, and the application's client secret is stored in a source code repository. The team also finds that the application's API is publicly accessible. What is the most critical attack path an attacker could exploit?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.