
EC-CouncilCloud Security Essentials
Domain 6Objective 5
Incident Response in the Cloud CSE Practice Questions (Page 2)
Part of the Cloud Security Monitoring and Incident Response domain, which makes up ~13% of our current practice bank.
49questions here
10free pages
8concepts
Questions 6–10
- 6
Your organization uses a hybrid cloud environment with on-premises and AWS resources. You need to detect incidents that span both environments. What is the best approach?
Select an answer first - 7
A company is responding to a security incident that involves a cloud provider's managed service. The incident response team needs to collect evidence and coordinate with the provider. The provider has a legal obligation to preserve evidence but also has a policy that limits access to certain logs. What is the best way to handle this situation?
Select an answer first - 8
A cloud incident involves a data breach in a multi-tenant environment. You need to collect evidence that may be used in legal proceedings. What is a critical consideration for maintaining chain of custody?
Select an answer first - 9
Your organization uses AWS CloudTrail to monitor API activity. You need to detect a potential compromised account that is making unusual API calls. What is the best way to detect this?
Select an answer first - 10
A cloud security analyst notices that an S3 bucket in AWS is publicly accessible and contains sensitive data. This is a common cloud security incident. What is the immediate containment action?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.