
EC-CouncilCloud Security Essentials
Domain 7Objective 3
Threat Modeling and Vulnerability Assessment CSE Practice Questions (Page 5)
Part of the Cloud Security Risk Assessment and Management domain, which makes up ~13% of our current practice bank.
48questions here
10free pages
6concepts
Questions 21–25
- 21
A security administrator is using OpenVAS to scan a cloud-hosted web application. The scan completes and reports a critical vulnerability in the web server version. However, the administrator knows that the web server is behind a load balancer that terminates TLS and forwards traffic on HTTP. What should the administrator do to ensure the scan results are accurate?
Select an answer first - 22
A security team is using STRIDE to threat model a cloud-based application that uses a managed database service. The team is concerned about the threat of data tampering. Which control is most effective in mitigating this threat?
Select an answer first - 23
A security architect is using the PASTA methodology to threat model a new cloud-based payment processing system. The team has already defined the business objectives and technical scope. According to PASTA, what should they do next?
Select an answer first - 24
A security analyst is using OpenVAS to scan a cloud-hosted web application. The scan completes and reports a critical vulnerability in the web server version. What is the next step in the vulnerability assessment process before remediation?
Select an answer first - 25
A security analyst is reviewing a cloud environment and discovers that an Amazon S3 bucket containing customer data is publicly readable. The bucket was created by a developer who used a pre-configured script. The analyst wants to identify the root cause and prevent similar issues. Which approach best combines threat modeling and vulnerability assessment to address this issue?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.