
EC-CouncilCloud Security Essentials
Domain 6Objective 5
Incident Response in the Cloud CSE Practice Questions (Page 9)
Part of the Cloud Security Monitoring and Incident Response domain, which makes up ~13% of our current practice bank.
49questions here
10free pages
8concepts
Questions 41–45
- 41
Which activity is typically part of the post-incident review (lessons learned) process?
Select an answer first - 42
Which of the following is a recommended practice for preserving digital evidence from a compromised cloud virtual machine?
Select an answer first - 43
A ransomware attack encrypts data in your cloud environment. You have identified the compromised VM and need to contain the threat. However, the VM contains critical evidence that may be needed for legal action. What is the best containment strategy that preserves evidence?
Select an answer first - 44
Your organization uses Google Cloud Platform (GCP) and wants to detect potential security incidents early. You need to set up a monitoring solution that can identify anomalous behavior across your cloud resources. What should you implement?
Select an answer first - 45
A company detects that a compromised service account is being used to access a cloud database and exfiltrate data. The incident response team wants to contain the threat while preserving evidence for investigation. What is the best containment action?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.