Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilNetwork Defense Essentials

Domain 4Objective 4

Cloud Security Risks, Attacks, and Best Practices NDE Practice Questions (Page 2)

Part of the Virtualization and Cloud Computing Security domain, which makes up ~12% of our current practice bank.

39questions here
8free pages
3concepts

Questions 6–10

  1. 6application · medium

    A financial services company uses a cloud-based customer relationship management (CRM) system. The security team wants to ensure that customer data is protected against unauthorized access and that any suspicious activity is quickly identified. They have already implemented encryption for data at rest and in transit. What is the next most important control to add?

    Select an answer first
  2. 7expert · hard

    A multinational company uses a public cloud IaaS environment. The security team has identified the following risks: (1) a misconfigured storage bucket that is publicly readable, (2) an API gateway that uses weak authentication, and (3) a lack of centralized logging. The company must remediate these risks while minimizing downtime and cost. Which approach best balances these constraints?

    Select an answer first
  3. 8application · medium

    A company's cloud environment is configured with a virtual private cloud (VPC) that has multiple subnets. The security team discovers that a database subnet is accessible from the internet due to a misconfigured route table. What is the most effective way to remediate this issue?

    Select an answer first
  4. 9expert · hard

    A company's cloud environment is under a sophisticated DDoS attack that is also exploiting a vulnerability in the application's API. The attack is causing the auto-scaling group to spin up many instances, increasing costs. The security team must stop the attack, minimize cost, and maintain service availability. Which sequence of actions is most effective?

    Select an answer first
  5. 10application · medium

    A company stores customer records in an S3 bucket. An auditor finds that the bucket policy allows 's3:GetObject' to 'Principal: *' but only from a specific VPC endpoint. The auditor flags this as a risk because the policy does not restrict which AWS accounts can access the bucket. What is the most effective way to reduce the risk of unauthorized data exposure while maintaining the required access pattern?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “NDE” is a trademark of its owner, used for identification only.