Skip to main content

312-40 Real Exam Questions

EC-Council Certified Cloud Security Engineer (CCSE)

147 questions available · Page 1 of 15

Updated Exam DumpsVerified AnswersPass Guarantee

Get Complete Exam Dumps
Question 1 Single choice

Chris Noth has recently joined CloudAppSec Private Ltd. as a cloud security engineer. Owing to several instances of malicious activities performed by former employees on his organization's applications and

data that reside in an on-premises environment, in 2010, his organization adopted cloud computing and migrated all applications and data to the cloud. Chris would like to manage user identities in cloud-based services and applications. Moreover, he wants to reduce the risk caused by the accounts of former users (employees) by ensuring that the users who leave the system can no longer log in to the system.
Therefore, he has enforced an IAM standard that can automate the provisioning and de-provisioning of users when they enter and leave the system.

Which of the following IAM standards is implemented by Chris Noth?

  1. A

    SCIM

  2. B

    XACML

  3. C

    OpenID

  4. D

    OAuth

Show answer and explanation

Correct answer: A

Question 2 Single choice

Melissa George is a cloud security engineer in an IT company. Her organization has adopted cloud-based services. The integration of cloud services has become significantly complicated to be managed by her organization. Therefore, her organization requires a third-party to consult, mediate, and facilitate the selection of a solution.

Which of the following NIST cloud deployment reference architecture actors manages cloud service usage, performance, and delivery, and maintains the relationship between the CSPs and cloud consumers?

  1. A

    Cloud Auditor

  2. B

    Cloud Carrier

  3. C

    Cloud Provider

  4. D

    Cloud Broker

Show answer and explanation

Correct answer: D

Question 3 Single choice

Richard Harris works as a senior cloud security engineer in a multinational company. His organization uses Microsoft Azure cloud-based services. Richard would like to manage, control, and monitor the access to important resources in his organization. Which service in Azure AD can enable Richard to manage, control, and monitor the access to resources in Azure. Azure AD.
and other Microsoft online services such as Microsoft Intune or Microsoft 365?

  1. A

    Privileged Identity Management

  2. B

    Federated Identity Management

  3. C

    Privileged Access Management

  4. D

    System for Cross-Domain Identity Management

Show answer and explanation

Correct answer: A

Question 4 Single choice

Rick Warren has been working as a cloud security engineer in an IT company for the past 4 years. Owing to the robust security features and various cost-effective services offered by AWS, in 2010, his organization migrated to the AWS cloud environment. While inspecting the intrusion detection system, Rick detected a security incident.

Which of the following AWS services collects logs from various data sources and stores them on a centralized location as logs files that can be used during forensic investigation in the event of a security incident?

  1. A

    Amazon CloudWatch

  2. B

    AWS CloudFormation

  3. C

    Amazon CloudFront

  4. D

    Amazon CloudTrail

Show answer and explanation

Correct answer: A

Question 5 Single choice

SecureSoft Solutions Pvt. Ltd. is an IT company that develops mobile-based applications. Owing to the secure and cost-effective cloud-based services provided by Google, the organization migrated its applications and data from on premises environment to Google cloud. Sienna Miller, a cloud security engineer, selected the Coldlinc Storage class for storing data in the Google cloud storage bucket.

What is the minimum storage duration for Coldline Storage?

  1. A

    60 days

  2. B

    120 days

  3. C

    50 days

  4. D

    90 days

Show answer and explanation

Correct answer: D

Question 6 Single choice

The GCP environment of a company named Magnitude IT Solutions encountered a security incident. To respond to the incident, the Google Data Incident Response Team was divided based on the different aspects of the incident.

Which member of the team has an authoritative knowledge of incidents and can be involved in different domains such as security, legal, product, and digital forensics?

  1. A

    Operations Lead

  2. B

    Subject Matter Experts

  3. C

    Incident Commander

  4. D

    Communications Lead

Show answer and explanation

Correct answer: B

Question 7 Single choice

A security incident has occurred within an organization's AWS environment. A cloud forensic investigation procedure is initiated for the acquisition of forensic evidence from the compromised EC2 instances.
However, it is essential to abide by the data privacy laws while provisioning any forensic instance and sending it for analysis.

What can the organization do initially to avoid the legal implications of moving data between two AWS regions for analysis?

  1. A

    Create evidence volume from the snapshot

  2. B

    Provision and launch a forensic workstation

  3. C

    Mount the evidence volume on the forensic workstation

  4. D

    Attach the evidence volume to the forensic workstation

Show answer and explanation

Correct answer: B

Question 8 Single choice

Kenneth Danziger has been working as a cloud security engineer in a multinational company. His organization uses AWS cloud-based services. Kenneth would like to review the changes in configuration and the relationships between AWS resources, examine the detailed resource configuration history, and determine the overall compliance of his organization against the configurations specified in internal guidelines.

Which of the following AWS services enables Kenneth to assess, audit, and evaluate the configuration of AWS resources?

  1. A

    AWS CloudTrail

  2. B

    AWS CloudFormation

  3. C

    AWS Config

  4. D

    AWS Security Hub

Show answer and explanation

Correct answer: C

Question 9 Single choice

Colin Farrell works as a senior cloud security engineer in a healthcare company. His organization has migrated all workloads and data in a private cloud environment. An attacker used the cloud environment as a point to disrupt the business of Colin's organization. Using intrusion detection prevention systems,
antivirus software, and log analyzers, Colin successfully detected the incident; however, a group of users were not able to avail the critical services provided by his organization.
Based on the incident impact level classification scales, select the severity of the incident encountered by Colin's organization?

  1. A

    High

  2. B

    None

  3. C

    Low

  4. D

    Medium

Show answer and explanation

Correct answer: A

Question 10 Single choice

You are the manager of a cloud-based security platform that offers critical services to government agencies and private companies. One morning, your team receives an alert from the platform's intrusion detection system indicating that there has been a potential breach in the system.
As the manager, which tool you will use for viewing and monitoring the sensitive data by scanning storage systems and reviewing the access rights to critical resources via a single centralized dashboard?

  1. A

    Google Cloud Security Command Center

  2. B

    Google Cloud Security Scanner

  3. C

    Cloud Identity and Access Management (IAM)

  4. D

    Google Cloud Armor

Show answer and explanation

Correct answer: A