
EC-CouncilCertified Security Specialist
Domain 4Objective 5
Cloud Computing Threats and Countermeasures ECSS Practice Questions (Page 5)
Part of the Ethical Hacking Advanced Attacks and Penetration Testing domain, which makes up ~17% of our current practice bank.
43questions here
9free pages
6concepts
Questions 21–25
- 21
A security analyst is investigating a potential account hijacking incident in a cloud environment. The analyst notices that a user account has been used to create new IAM roles and modify security groups. What is the most likely attack vector?
Select an answer first - 22
A security architect is designing a multi-tier application in a public cloud. The application consists of a web tier, an application tier, and a database tier. The architect needs to ensure that the database tier is not accessible from the internet, but the application tier must be able to connect to it. Additionally, the architect wants to minimize the attack surface. Which network design should be used?
Select an answer first - 23
A developer accidentally exposed cloud API keys in a public code repository. An attacker uses these keys to access the cloud environment. Which of the following is the MOST effective immediate countermeasure?
Select an answer first - 24
A multinational company must comply with GDPR and is using a public cloud provider. The company stores personal data of EU citizens in a specific region. What is the most important consideration to ensure GDPR compliance?
Select an answer first - 25
Which cloud attack vector involves an attacker exploiting the cloud instance metadata service to retrieve temporary credentials or other sensitive information?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.