
EC-CouncilCloud Security Essentials
Domain 2Objective 2
Role-Based Access Control (RBAC) CSE Practice Questions (Page 1)
Part of the Identity and Access Management in the Cloud domain, which makes up ~12% of our current practice bank.
48questions here
10free pages
10concepts
Questions 1–5
- 1
In role-based access control, what is the primary reason for assigning permissions to roles rather than to individual users?
Select an answer first - 2
A company has a 'Database Backup Operator' role that includes permissions to read all databases, write to the backup storage, and delete old backups. An audit reveals that the role is over-privileged because operators only need to initiate backups and manage the backup storage, not read database contents. Which change best reduces the risk?
Select an answer first - 3
A large enterprise uses a cloud RBAC system with a deep role hierarchy. A security audit reveals that a user assigned to a senior role has inherited permissions from multiple junior roles, including a permission that conflicts with another permission they hold, violating separation of duties. The enterprise wants to maintain the hierarchy for operational efficiency but must eliminate the conflict. Which approach best resolves the issue?
Select an answer first - 4
In a cloud RBAC system, what does a role assignment do?
Select an answer first - 5
An organization is implementing RBAC for a change-management process. They need to ensure that the person who approves a change is different from the person who implements it. Which RBAC configuration enforces this?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.