
EC-CouncilCloud Security Essentials
Domain 7Objective 1
Identifying Cloud Security Risks CSE Practice Questions (Page 9)
Part of the Cloud Security Risk Assessment and Management domain, which makes up ~13% of our current practice bank.
45questions here
9free pages
7concepts
Questions 41–45
- 41
Which cloud-specific risk is most directly caused by multi-tenancy?
Select an answer first - 42
A threat modeling session for a cloud application reveals that an attacker could exploit a misconfigured storage bucket to access sensitive data. The team wants to systematically identify other similar attack vectors. Which technique should they use next?
Select an answer first - 43
A company is adopting a cloud service where the provider manages the operating system and application runtime, but the customer is responsible for its own data and user access. The security team is identifying risks. Which risk is most directly associated with the customer's responsibilities in this shared responsibility model?
Select an answer first - 44
A company stores a mix of data in the cloud: public marketing brochures, internal project plans, and customer personal data. The security team is planning a risk assessment. How should they classify these assets to prioritize their efforts?
Select an answer first - 45
A security architect is threat modeling a new cloud application that will process sensitive financial data. The application consists of a web front end, an API layer, and a database, all deployed in a public cloud. The architect wants to systematically identify attack vectors. Which approach best aligns with threat modeling principles for this cloud architecture?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CSE
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.