
EC-CouncilCloud Security Essentials
Domain 5Objective 1
Secure Software Development Lifecycle (SDLC) in the Cloud CSE Practice Questions (Page 7)
Part of the Application Security in the Cloud domain, which makes up ~16% of our current practice bank.
48questions here
10free pages
10concepts
Questions 31–35
- 31
A financial services company is developing a cloud application that handles customer data. They must comply with a regulation that requires data to be stored in a specific geographic region. During which SDLC phase should this requirement be formally captured?
Select an answer first - 32
A company is designing a multi-tier web application in the cloud. The threat model identifies a risk of an attacker compromising the web tier and using that access to reach the database tier. The security team wants to minimize this risk without adding significant latency. Which control is the MOST effective and practical?
Select an answer first - 33
A developer is writing a cloud function that accepts JSON input from an API gateway and stores it in a database. Which secure coding practice is MOST important to prevent injection attacks?
Select an answer first - 34
When threat modeling a cloud application, which element is unique to the cloud and must be included in the data flow diagram?
Select an answer first - 35
Which practice is important for securing APIs used by a cloud application?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.