Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCloud Security Essentials

Domain 2Objective 2

Role-Based Access Control (RBAC) CSE Practice Questions (Page 6)

Part of the Identity and Access Management in the Cloud domain, which makes up ~12% of our current practice bank.

48questions here
10free pages
10concepts

Questions 26–30

  1. 26expert · hard

    A company has a high rate of employee turnover. They want to ensure that when an employee leaves, their cloud access is revoked quickly and completely. They also want to avoid accumulating unused roles. Which RBAC best practice addresses this?

    Select an answer first
  2. 27expert · hard

    A company is implementing RBAC for a procurement system. They have a requirement that a user cannot both create a purchase order and approve it. They also have a requirement that a user cannot both approve a purchase order and receive the goods. The RBAC system supports role hierarchies. Which design enforces both separation of duties constraints?

    Select an answer first
  3. 28application · medium

    A cloud security team is designing RBAC roles for a financial application. The same person must never be able to both create a vendor invoice and approve that invoice for payment. Which RBAC design decision directly enforces this requirement?

    Select an answer first
  4. 29expert · medium

    An organization is designing a role hierarchy for a software development team. They have the following roles: 'Engineer', 'Senior Engineer', and 'Tech Lead'. The 'Senior Engineer' role should inherit from 'Engineer', and the 'Tech Lead' role should inherit from 'Senior Engineer'. The 'Engineer' role has permissions to deploy to staging. The 'Senior Engineer' role adds permissions to deploy to production. The 'Tech Lead' role adds permissions to manage team members. Which statement about the effective permissions of a user assigned to the 'Tech Lead' role is correct?

    Select an answer first
  5. 30expert · hard

    A company operates in both AWS and Azure. In AWS, they use IAM roles with inline policies for a legacy application. In Azure, they use built-in roles. The company is standardizing on least privilege and wants to reduce the number of custom policies. Which approach best achieves this across both providers?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.