
EC-CouncilCloud Security Essentials
Domain 5Objective 5
Serverless and Container Security (Docker, Kubernetes) CSE Practice Questions (Page 5)
Part of the Application Security in the Cloud domain, which makes up ~16% of our current practice bank.
54questions here
11free pages
10concepts
Questions 21–25
- 21
Which Kubernetes resource is used to restrict network traffic between pods?
Select an answer first - 22
A company is designing a container security strategy. They have a mix of legacy applications that require root privileges and new applications that can run as non-root. The security team wants to minimize the risk of container escape while maintaining operational compatibility. Which approach should they take?
Select an answer first - 23
A company wants to secure its container supply chain. They currently build images in a CI/CD pipeline and push them to a private registry. They want to ensure that only images that have passed security scanning and are signed by the CI/CD system can be deployed. They also want to prevent developers from manually pushing images to the registry. Which set of controls should they implement?
Select an answer first - 24
A serverless application processes sensitive personal data. The compliance team requires that data be encrypted at rest and in transit, and that access to the data be logged. The application uses a managed database service. Which combination of controls should the team implement?
Select an answer first - 25
A Kubernetes cluster is shared by multiple teams. One team has a workload that requires access to a specific external API, but the security team wants to enforce least privilege and minimize the risk of lateral movement. They also want to ensure that the workload can only access the API and not other internal services. Which set of controls should they implement?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.