
EC-CouncilCloud Security Essentials
Domain 6Objective 5
Incident Response in the Cloud CSE Practice Questions (Page 3)
Part of the Cloud Security Monitoring and Incident Response domain, which makes up ~13% of our current practice bank.
49questions here
10free pages
8concepts
Questions 11–15
- 11
After a ransomware incident in your cloud environment, you have contained the threat and eradicated the malware. You now need to restore services to normal operation. Which step should be part of the recovery phase?
Select an answer first - 12
Which of the following is an effective containment strategy for a compromised cloud resource?
Select an answer first - 13
After a cloud incident is resolved, your organization wants to improve its incident response capabilities. Which activity is most important for the post-incident phase?
Select an answer first - 14
A company is designing an incident response plan for a serverless architecture using AWS Lambda and API Gateway. The security team wants to ensure that the plan accounts for the unique aspects of serverless, such as ephemeral execution environments and limited visibility. What is the most important element to include in the plan?
Select an answer first - 15
A company uses AWS CloudTrail, Amazon GuardDuty, and AWS Config to monitor its cloud environment. An analyst wants to ensure that any new IAM user creation is detected and alerted in near real-time. What is the most effective method?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.