Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCloud Security Essentials

Domain 5Objective 3

Secure Coding Practices CSE Practice Questions (Page 6)

Part of the Application Security in the Cloud domain, which makes up ~16% of our current practice bank.

60questions here
12free pages
12concepts

Questions 26–30

  1. 26expert · hard

    A team is designing a cloud-based healthcare application that will store patient records. They need to comply with data protection regulations and want to identify potential threats to patient data. Which threat modeling approach is most effective?

    Select an answer first
  2. 27expert · hard

    A team is developing a REST API that accepts JSON payloads. The API is used by a mobile app and a web dashboard. The security team found that the API is vulnerable to SQL injection via a search parameter. The team wants to fix it without changing the API contract. Which remediation is most effective?

    Select an answer first
  3. 28foundation · easy

    What is the main goal of output encoding in a web application?

    Select an answer first
  4. 29expert · hard

    A company is migrating a legacy application to the cloud. The application stores user passwords using MD5 hashes. The security team wants to improve password storage. The application must remain compatible with existing user accounts. What is the best approach?

    Select an answer first
  5. 30application · medium

    A web application stores user passwords in a cloud database. The security team wants to ensure that even if the database is compromised, passwords cannot be easily reversed. Which practice should the team adopt?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.