Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCloud Security Essentials

Domain 7Objective 3

Threat Modeling and Vulnerability Assessment CSE Practice Questions (Page 9)

Part of the Cloud Security Risk Assessment and Management domain, which makes up ~13% of our current practice bank.

48questions here
10free pages
6concepts

Questions 41–45

  1. 41application · medium

    A company is migrating a legacy web application to AWS. The security team is conducting a threat modeling exercise using STRIDE. They are focusing on the application's authentication mechanism, which uses a shared secret embedded in the client code. Which STRIDE category is most directly applicable to this weakness, and what is the most appropriate initial mitigation?

    Select an answer first
  2. 42application · medium

    A company uses a cloud provider's managed database service. The provider is responsible for patching the database engine, but the company must manage access controls and data encryption. During a threat modeling session, the team identifies a risk that a former employee's credentials might still be valid. Which shared responsibility gap does this risk highlight?

    Select an answer first
  3. 43application · medium

    A security team is using Nessus to scan a cloud environment that includes both Windows and Linux virtual machines. The scan completes and reports several vulnerabilities. The team lead wants to ensure the scan results are accurate and actionable. Which step should the team take?

    Select an answer first
  4. 44application · medium

    A security analyst is creating an attack tree for a cloud-based customer relationship management (CRM) system. The root goal is 'attacker gains access to customer data.' Which of the following is a valid child node in the attack tree?

    Select an answer first
  5. 45expert · hard

    A large enterprise is migrating a critical application to the cloud. The security team must choose a threat modeling methodology. They need to align threat modeling with business objectives and provide a risk-centric view that can be used by executives. They also need to trace threats to specific attack paths. Which methodology best fits these requirements?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.