
EC-CouncilCloud Security Essentials
Domain 5Objective 1
Secure Software Development Lifecycle (SDLC) in the Cloud CSE Practice Questions (Page 9)
Part of the Application Security in the Cloud domain, which makes up ~16% of our current practice bank.
48questions here
10free pages
10concepts
Questions 41–45
- 41
A team is designing a cloud application that will be accessed by external partners. The security team mandates that the application should be secure by default, meaning that any new feature must be disabled unless explicitly enabled by an administrator. Which design principle is being applied?
Select an answer first - 42
A developer is writing code for a cloud application that accepts JSON input from external clients. The code parses the JSON and uses the values in database queries. Which secure coding practice is most important to prevent injection attacks?
Select an answer first - 43
A DevOps team is implementing DevSecOps in a regulated industry. They need to ensure that every code change is automatically tested for security vulnerabilities and that compliance evidence is collected. However, they also need to maintain a fast release cadence. Which approach BEST balances security and speed?
Select an answer first - 44
Which practice supports governance in a cloud SDLC by ensuring that security policies are enforced across development teams?
Select an answer first - 45
A team is threat modeling a new cloud-native application that uses serverless functions, a managed database, and an object storage bucket. Which threat is MOST specific to the serverless component and should be prioritized?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.