
EC-CouncilCloud Security Essentials
Domain 2Objective 5
IAM Auditing and Monitoring CSE Practice Questions (Page 4)
Part of the Identity and Access Management in the Cloud domain, which makes up ~12% of our current practice bank.
36questions here
8free pages
5concepts
Questions 16–20
- 16
A security engineer needs to ensure that all IAM changes, such as policy modifications and role assignments, are recorded for later analysis. The cloud provider's IAM service supports audit logging. What should the engineer do?
Select an answer first - 17
A security team wants to be notified when a user fails to authenticate more than five times within a 10-minute window. The team uses AWS IAM and CloudTrail. What is the most effective way to implement this alert?
Select an answer first - 18
A company must produce a compliance report showing that all IAM users have not used their passwords for more than 90 days. The company uses Google Cloud. What is the most efficient way to generate this report?
Select an answer first - 19
An organization's IAM audit logs show that a user has been logging in from a new device and then immediately changing their password. This has happened three times in the past week. The user is a remote employee who recently got a new laptop. The organization has a policy that requires investigation of any password change. What should the organization do?
Select an answer first - 20
A company must comply with a regulation that requires quarterly reviews of all IAM policies and user access rights. The company uses Google Cloud. What is the most efficient way to automate this compliance reporting?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.