
EC-CouncilCertified Security Specialist
Domain 2Objective 1
Virtualization and Cloud Computing Security ECSS Practice Questions (Page 8)
Part of the Network Defense Systems and Monitoring domain, which makes up ~14% of our current practice bank.
50questions here
10free pages
8concepts
Questions 36–40
- 36
A small business migrates its customer database to a cloud PaaS offering. The provider manages the runtime environment and applies OS patches, but the business is responsible for the application code and data. A data breach occurs because the application's database queries are vulnerable to SQL injection. Who is primarily responsible for this vulnerability?
Select an answer first - 37
A company runs a Type 1 hypervisor with multiple production VMs. An administrator discovers that a VM kernel module can read host memory. Which risk is being exploited, and what immediate control should be applied?
Select an answer first - 38
A company is evaluating a SaaS email service. They want to ensure that emails are encrypted in transit and at rest. Which party is responsible for implementing encryption at rest for the email data?
Select an answer first - 39
Which cloud deployment model is characterized by infrastructure that is shared by several organizations with a common interest, such as a specific industry or compliance requirement?
Select an answer first - 40
Why is compliance with regulations such as GDPR important when using cloud services?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.