
EC-CouncilNetwork Defense Essentials
Domain 4Objective 4
Cloud Security Risks, Attacks, and Best Practices NDE Practice Questions (Page 7)
Part of the Virtualization and Cloud Computing Security domain, which makes up ~12% of our current practice bank.
39questions here
8free pages
3concepts
Questions 31–35
- 31
Which cloud security best practice ensures that users have only the permissions necessary to perform their job functions?
Select an answer first - 32
A security analyst is reviewing cloud access logs and notices that a user account has been making API calls from an IP address in a country where the company has no operations. The user is a system administrator. What should the analyst do first?
Select an answer first - 33
A company uses a cloud-based customer database. The database is accessible from the internet through a public endpoint. The security team is concerned about the risk of a data breach due to misconfigured security groups. What is the most effective way to reduce the attack surface?
Select an answer first - 34
Which of the following is a common cloud security risk that occurs when cloud resources are left accessible to the public due to incorrect configuration settings?
Select an answer first - 35
A company's cloud environment is experiencing a data breach. The security team has identified that the attacker used a compromised API key to access a storage bucket containing customer data. The team needs to contain the breach while preserving evidence for forensic analysis. Which sequence of actions is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “NDE” is a trademark of its owner, used for identification only.