Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Security Specialist

Domain 4Objective 5

Cloud Computing Threats and Countermeasures ECSS Practice Questions (Page 6)

Part of the Ethical Hacking Advanced Attacks and Penetration Testing domain, which makes up ~17% of our current practice bank.

43questions here
9free pages
6concepts

Questions 26–30

  1. 26foundation · easy

    Which statement correctly defines the cloud computing service model known as Platform as a Service (PaaS)?

    Select an answer first
  2. 27application · medium

    A company hosts a web application on a public cloud VM. The application makes HTTP requests to a third-party service using credentials stored in environment variables. An attacker exploits a server-side request forgery (SSRF) vulnerability in the application and accesses the cloud metadata service. What is the MOST LIKELY immediate impact?

    Select an answer first
  3. 28foundation · easy

    Which of the following is a common cloud-specific threat that arises when organizations fail to properly configure their cloud resources, such as leaving storage buckets publicly accessible?

    Select an answer first
  4. 29application · medium

    A company is migrating to a public cloud and wants to ensure that their security policies are consistently applied across all resources. They also need to meet compliance requirements for auditing. Which tool should they use?

    Select an answer first
  5. 30application · medium

    A startup uses a public cloud IaaS environment. After a security review, they discover that a developer accidentally left a cloud storage bucket publicly readable, exposing customer data. Which combination of controls would BEST prevent this class of incident in the future?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.