Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCloud Security Essentials

Domain 7Objective 3

Threat Modeling and Vulnerability Assessment CSE Practice Questions (Page 1)

Part of the Cloud Security Risk Assessment and Management domain, which makes up ~13% of our current practice bank.

48questions here
10free pages
6concepts

Questions 1–5

  1. 1expert · hard

    A security architect is threat modeling a cloud-native application that uses microservices. The architect needs to identify threats related to service-to-service communication. Which threat modeling approach is most suitable for this task?

    Select an answer first
  2. 2foundation · easy

    What is a key feature of OpenVAS as a vulnerability scanning tool?

    Select an answer first
  3. 3application · medium

    A vulnerability scan identifies a medium-severity vulnerability in a cloud-based application. The vulnerability is not currently exploitable due to network segmentation, but the segmentation is scheduled to be removed next month. What should the security team do?

    Select an answer first
  4. 4application · medium

    A company is migrating a legacy three-tier application to AWS. The security team is conducting a threat modeling exercise using STRIDE. They are analyzing the data flow between the web tier and the database tier. Which STRIDE category is most directly relevant to the risk of an attacker modifying SQL queries sent from the web tier to the database?

    Select an answer first
  5. 5foundation · easy

    When prioritizing vulnerabilities for remediation, which factor is most important to consider?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.