
EC-CouncilCloud Security Essentials
Domain 4Objective 5
Firewalls and Intrusion Detection CSE Practice Questions (Page 5)
Part of the Network Security in the Cloud domain, which makes up ~10% of our current practice bank.
50questions here
10free pages
12concepts
Questions 21–25
- 21
What is the key difference between a stateful and a stateless firewall?
Select an answer first - 22
Which tool is commonly used to centralize and analyze firewall and IDS logs in a cloud environment?
Select an answer first - 23
A security team is investigating a potential breach. They need to determine whether a specific VM communicated with an external IP address over the past 30 days. Which data source should they query first?
Select an answer first - 24
Which of the following is a common detection method used by an Intrusion Detection System (IDS)?
Select an answer first - 25
A company is deploying a cloud-based IDS/IPS solution. They have a mix of workloads: some are in a VPC with a single subnet, and others are in a separate VPC connected via peering. They want to monitor all east-west traffic and block malicious activity. They are considering two options: a managed IDS/IPS service that can be enabled on VPCs, or a third-party IPS virtual appliance in a central VPC. Which factor should most influence their decision?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.