
EC-CouncilCloud Security Essentials
Domain 3Objective 2
Encryption at Rest and in Transit CSE Practice Questions (Page 7)
Part of the Data Protection and Encryption in the Cloud domain, which makes up ~12% of our current practice bank.
55questions here
11free pages
15concepts
Questions 31–35
- 31
Why do compliance regulations often mandate encryption?
Select an answer first - 32
A company must comply with a regulation that requires encryption keys to be stored separately from the encrypted data. They are using a cloud object storage service. They also want to minimize the risk of data exposure if the storage account is compromised. Which approach should they choose?
Select an answer first - 33
A company uses a cloud KMS to manage encryption keys. The security team wants to ensure that if a key is compromised, the impact is limited and the key can be replaced without re-encrypting all data. Which practice should they implement?
Select an answer first - 34
What is the purpose of a key encryption key (KEK) in envelope encryption?
Select an answer first - 35
What is the primary purpose of a VPN for data in transit?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.