
EC-CouncilCloud Security Essentials
Domain 3Objective 2
Encryption at Rest and in Transit CSE Practice Questions (Page 11)
Part of the Data Protection and Encryption in the Cloud domain, which makes up ~12% of our current practice bank.
55questions here
11free pages
15concepts
Questions 51–55
- 51
How is encryption typically applied to cloud object storage, such as Amazon S3?
Select an answer first - 52
A security team is designing a key management strategy for a multi-cloud environment. They need to ensure that keys are available across different cloud providers and that key rotation is coordinated. Which approach should they use?
Select an answer first - 53
A company stores sensitive documents in a cloud object storage bucket. The security team wants to encrypt the data with a customer-managed key that can be rotated without re-encrypting the stored objects. Which approach should they use?
Select an answer first - 54
What is the main purpose of encryption in transit?
Select an answer first - 55
A company is using a cloud KMS to manage keys for envelope encryption. They need to ensure that key material is protected against unauthorized access, and they want to meet a compliance requirement that keys be stored in a hardware security module (HSM). Which KMS feature should they use?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CSE
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.