
EC-CouncilCloud Security Essentials
Domain 2Objective 1
IAM Fundamentals, Principals, and Roles CSE Practice Questions (Page 2)
Part of the Identity and Access Management in the Cloud domain, which makes up ~12% of our current practice bank.
31questions here
7free pages
6concepts
Questions 6–10
- 6
A cloud security team needs to grant a third-party auditor temporary read-only access to audit logs in an AWS account. The auditor does not have an identity in the company's identity provider. Which approach should the team use?
Select an answer first - 7
A company has a policy that only the 'DatabaseAdmin' role can modify production database settings. A user in the 'Developer' group needs to occasionally view database configuration but not modify it. What should the IAM administrator do?
Select an answer first - 8
An organization has a compliance requirement that no single user can both approve and execute changes to production infrastructure. They use RBAC. Which configuration enforces this separation of duties?
Select an answer first - 9
A security auditor recommends that no single user should have both the ability to create new IAM users and the ability to delete IAM users. Which IAM best practice does this recommendation primarily address?
Select an answer first - 10
A developer requests full administrator access to all cloud resources to 'make things easier.' The security team wants to follow the principle of least privilege. What is the best response?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.