
EC-CouncilCloud Security Essentials
Domain 6Objective 5
Incident Response in the Cloud CSE Practice Questions (Page 4)
Part of the Cloud Security Monitoring and Incident Response domain, which makes up ~13% of our current practice bank.
49questions here
10free pages
8concepts
Questions 16–20
- 16
What is the primary goal of the recovery phase in cloud incident response?
Select an answer first - 17
Which cloud service is commonly used to collect and analyze security-related logs and events for incident detection?
Select an answer first - 18
During a security incident involving a compromised Azure VM, the incident response team needs to collect forensic evidence that may be used in legal proceedings. The VM is still running and the team suspects the attacker may have modified system files. What is the most appropriate approach to preserve evidence while maintaining chain of custody?
Select an answer first - 19
A security analyst detects that a container in a Kubernetes cluster is communicating with a known command-and-control server. The cluster runs a critical production application. What is the most effective containment action that minimizes disruption to the application?
Select an answer first - 20
After a cloud incident, your organization wants to recover services while also improving future incident response. You have limited resources and need to balance recovery speed with learning. What is the most effective approach?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.