
EC-CouncilCloud Security Essentials
Domain 4Objective 2
Network Isolation and Segmentation CSE Practice Questions (Page 4)
Part of the Network Security in the Cloud domain, which makes up ~10% of our current practice bank.
31questions here
7free pages
6concepts
Questions 16–20
- 16
How does network isolation help contain a security breach in a cloud environment?
Select an answer first - 17
A security analyst is reviewing the network architecture of a cloud environment. The environment has a single VPC with multiple subnets, and all resources are in the same security group. The analyst wants to reduce the attack surface and contain a potential breach. Which change would be most effective?
Select an answer first - 18
Which cloud network construct provides a logically isolated section of the cloud where you can launch resources in a virtual network that you define?
Select an answer first - 19
A large enterprise is migrating to a multi-cloud environment (AWS and Azure) and wants to enforce consistent network isolation between application tiers across both clouds. The security team requires that the web tier in AWS can communicate with the application tier in Azure, but the database tier in either cloud must not be reachable from the other cloud. They also need to audit all cross-cloud traffic. What is the most appropriate approach?
Select an answer first - 20
A security team has implemented network segmentation in their cloud environment. To ensure the segmentation is effective, they want to continuously verify that traffic between segments is restricted as intended. Which approach is most effective for this verification?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.