
EC-CouncilCloud Security Essentials
Domain 2Objective 4
Multifactor Authentication and Least Privilege CSE Practice Questions (Page 10)
Part of the Identity and Access Management in the Cloud domain, which makes up ~12% of our current practice bank.
50questions here
10free pages
8concepts
Questions 46–50
- 46
A company is deploying MFA and wants to protect against phishing attacks that use real-time relay to bypass TOTP codes. Which MFA method should they choose to be phishing-resistant?
Select an answer first - 47
Which of the following is an example of applying least privilege in a cloud environment?
Select an answer first - 48
A cloud administrator is setting up MFA for a user. The user already has a password (knowledge factor). Which additional factor should the administrator add to satisfy the 'something you have' factor?
Select an answer first - 49
A company is rolling out MFA to all employees. They are worried about user resistance due to the extra step. What is a best practice to reduce user friction while maintaining security?
Select an answer first - 50
An organization is deploying MFA for a remote workforce that uses both corporate laptops and personal mobile devices. The security team is concerned about phishing attacks that trick users into entering one-time codes on fake websites. Which MFA method is most effective against such phishing?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CSE
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.