
EC-CouncilCloud Security Essentials
Domain 1Objective 4
Threats and Attacks in Cloud Environments CSE Practice Questions (Page 11)
Part of the Cloud Computing and Security Fundamentals domain, which makes up ~12% of our current practice bank.
56questions here
12free pages
11concepts
Questions 51–55
- 51
A company exposes a public REST API for its cloud application. The API uses API keys passed in the query string for authentication. An attacker intercepts network traffic and captures a valid API key, then uses it to access sensitive data. What is the most effective mitigation?
Select an answer first - 52
A startup uses a single AWS account for all environments. A developer accidentally creates an S3 bucket with 'Everyone' read access, and the bucket name is publicly discoverable. The security team wants to prevent this class of incident from recurring without blocking the developers' ability to create buckets. Which combination of controls should the security team implement?
Select an answer first - 53
What is the primary impact of a distributed denial-of-service (DDoS) attack on a cloud service?
Select an answer first - 54
A company is evaluating a public cloud provider for a new application that will process sensitive financial data. The company is concerned about the risk of multi-tenant data exposure due to shared infrastructure. Which of the following controls would best address this concern?
Select an answer first - 55
A security researcher is testing a cloud provider's container service. The researcher suspects that a container can access the host kernel and potentially read data from other containers on the same node. Which type of vulnerability is the researcher investigating, and what is the most effective mitigation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.