Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCloud Security Essentials

Domain 5Objective 5

Serverless and Container Security (Docker, Kubernetes) CSE Practice Questions (Page 4)

Part of the Application Security in the Cloud domain, which makes up ~16% of our current practice bank.

54questions here
11free pages
10concepts

Questions 16–20

  1. 16expert · hard

    A company runs containers on a shared Kubernetes cluster. The security team is evaluating whether to use a container runtime with stronger isolation, such as gVisor or Kata Containers, for untrusted workloads. However, these runtimes have performance overhead. Which approach best balances security and performance?

    Select an answer first
  2. 17foundation · easy

    What is a primary purpose of runtime security monitoring for containers?

    Select an answer first
  3. 18foundation · easy

    What is a recommended best practice for securing serverless function code?

    Select an answer first
  4. 19application · medium

    A company runs a serverless function that processes user-uploaded images. The function currently uses an admin AWS IAM role that can access all S3 buckets and DynamoDB tables. During a review, the security team finds that the function only needs to read from one S3 bucket and write to one DynamoDB table. The team also wants to ensure that the function's dependencies are scanned for known vulnerabilities before deployment. Which combination of actions best addresses the principle of least privilege and the dependency risk?

    Select an answer first
  5. 20foundation · easy

    Which practice is essential for detecting security incidents in serverless functions?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.