
EC-CouncilCloud Security Essentials
Domain 7Objective 3
Threat Modeling and Vulnerability Assessment CSE Practice Questions (Page 6)
Part of the Cloud Security Risk Assessment and Management domain, which makes up ~13% of our current practice bank.
48questions here
10free pages
6concepts
Questions 26–30
- 26
A security team is conducting a vulnerability assessment of a cloud-based application. They have completed the scanning phase and identified several vulnerabilities. The team lead wants to ensure the findings are properly analyzed and reported. Which step is most critical to perform after scanning and before remediation?
Select an answer first - 27
Which cloud-specific threat involves gaps in responsibility between the cloud provider and the customer?
Select an answer first - 28
Which step in the vulnerability assessment process involves verifying that a reported vulnerability is real and not a false positive?
Select an answer first - 29
A vulnerability scan of a cloud environment reveals the following findings: (1) an S3 bucket with public read access containing non-sensitive marketing files, (2) a critical remote code execution vulnerability in a public-facing web application, and (3) a medium-severity SSL misconfiguration on an internal admin portal. The security team has limited resources and must prioritize remediation. Which vulnerability should be addressed first?
Select an answer first - 30
A security team is conducting a vulnerability assessment of a cloud environment that includes both production and development environments. The team has limited time and must decide which environment to scan first. The production environment contains customer data, while the development environment is used for testing new features. Which approach is the most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.