
EC-CouncilCertified Incident Handler
Domain 4Objective 2
Handling and Responding to Cloud Security Incidents ECIH Practice Questions (Page 4)
Part of the Web Application and Cloud Incidents domain, which makes up ~18% of our current practice bank.
48questions here
10free pages
6concepts
Questions 16–20
- 16
Which of the following is a common method for detecting security incidents in a cloud environment?
Select an answer first - 17
What is the primary purpose of revoking compromised credentials during a cloud security incident?
Select an answer first - 18
After a cloud incident, the incident handler is conducting a post-incident review. The organization wants to improve its cloud security posture. Which action is most effective?
Select an answer first - 19
A company experiences a data breach in its PaaS application. The incident handler needs to contain the incident and then recover. The application uses a managed database and a web service. Which sequence of actions is most effective?
Select an answer first - 20
A security team is designing a detection strategy for a cloud environment that uses IaaS and SaaS. They need to detect incidents that involve compromised credentials and data exfiltration. Which combination of monitoring sources is most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECIH” is a trademark of its owner, used for identification only.