Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCloud Security Essentials

Domain 1Objective 4

Threats and Attacks in Cloud Environments CSE Practice Questions (Page 8)

Part of the Cloud Computing and Security Fundamentals domain, which makes up ~12% of our current practice bank.

56questions here
12free pages
11concepts

Questions 36–40

  1. 36expert · hard

    A company's cloud administrator receives a phone call from someone claiming to be from the cloud provider's support team. The caller asks the administrator to verify their password and provide a one-time passcode to 'resolve a security issue'. The administrator complies. Shortly after, the administrator's account is used to create a new admin user. What is the most likely attack, and what control would have prevented it?

    Select an answer first
  2. 37expert · hard

    A company runs a latency-sensitive application in a single cloud region. They are experiencing intermittent DDoS attacks that cause brief outages. The security team is evaluating mitigation options. Which solution provides the best balance of availability, cost, and complexity?

    Select an answer first
  3. 38foundation · easy

    What is a resource exhaustion attack in a cloud environment?

    Select an answer first
  4. 39foundation · easy

    What is session hijacking in a cloud context?

    Select an answer first
  5. 40application · medium

    A company's cloud environment experienced a breach. The investigation reveals that an attacker used a valid user's credentials to access the cloud console from an IP address in a foreign country, and the user's password had been reused from a previous breach. Which combination of controls would most effectively reduce the risk of this type of attack recurring?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.