
EC-CouncilCloud Security Essentials
Domain 5Objective 2
Web Application Firewall (WAF) and OWASP Top Ten CSE Practice Questions (Page 4)
Part of the Application Security in the Cloud domain, which makes up ~16% of our current practice bank.
65questions here
13free pages
16concepts
Questions 16–20
- 16
Why is insufficient logging and monitoring a security risk?
Select an answer first - 17
What is a common vulnerability related to broken authentication?
Select an answer first - 18
A company's web application was recently compromised due to a misconfigured server that exposed internal directories. The security team wants to use a WAF to mitigate similar misconfigurations. Which WAF policy is most effective?
Select an answer first - 19
What is the primary goal of sensitive data exposure prevention?
Select an answer first - 20
A retail company's e-commerce site, fronted by a cloud WAF, is experiencing a spike in failed login attempts that include SQL syntax in the username field. The security team wants to block these requests immediately without disrupting legitimate users who occasionally mistype their credentials. What should the WAF administrator configure?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.