
EC-CouncilCloud Security Essentials
Domain 7Objective 3
Threat Modeling and Vulnerability Assessment CSE Practice Questions (Page 2)
Part of the Cloud Security Risk Assessment and Management domain, which makes up ~13% of our current practice bank.
48questions here
10free pages
6concepts
Questions 6–10
- 6
A company uses a multi-cloud environment with workloads in AWS and Azure. The security team is conducting a threat modeling exercise and wants to identify threats that are unique to cloud computing. Which threat should be included in the threat model?
Select an answer first - 7
Which remediation strategy is most aligned with cloud security best practices for a misconfigured storage bucket?
Select an answer first - 8
A vulnerability scan reveals a critical remote code execution vulnerability in a web server that is not directly exposed to the internet but is accessible from the internal network. The server hosts a legacy application that cannot be patched immediately. What is the most appropriate risk treatment?
Select an answer first - 9
What is the primary purpose of a vulnerability assessment?
Select an answer first - 10
A cloud security team is setting up vulnerability scanning for a new Kubernetes cluster. They plan to use Nessus to scan the cluster's worker nodes. What is a critical consideration for this scanning approach?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.