
EC-CouncilCloud Security Essentials
Domain 1Objective 4
Threats and Attacks in Cloud Environments CSE Practice Questions (Page 7)
Part of the Cloud Computing and Security Fundamentals domain, which makes up ~12% of our current practice bank.
56questions here
12free pages
11concepts
Questions 31–35
- 31
Which of the following is an example of an insider threat from cloud provider personnel?
Select an answer first - 32
A company uses a cloud-based identity provider (IdP) for single sign-on (SSO). An attacker obtains a valid session token for a user by intercepting the token in transit. The attacker then uses the token to access the user's cloud resources. Which of the following is the most effective control to prevent this type of session hijacking?
Select an answer first - 33
A cloud provider discovers a vulnerability in its virtualization platform that could allow a guest VM to read the memory of other VMs on the same host. The provider plans to patch the hypervisor, but the patch requires a host reboot. What is the most important consideration for the provider to maintain security while minimizing downtime?
Select an answer first - 34
Which of the following is a classic example of a cloud misconfiguration leading to a security incident?
Select an answer first - 35
What is a key characteristic of the evolving cloud threat landscape compared to traditional on-premises environments?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.