ECCouncil 312-40 - Certified Cloud Security Engineer Exam
Page: 3 / 30
Total 147 questions
Question #11 (Topic: Exam A)
Samuel Jackson has been working as a cloud security engineer for the past 12 years in VolkSec Pvt. Ltd., whose applications are hosted in a private cloud. Owing to the increased number of users for its services, the organizations is finding it difficult to manage the on-premises data center. To overcome scalability and data storage issues, Samuel advised the management of his organization to migrate to a public cloud and shift the applications and data. Once the suggestion to migrate to public cloud was accepted by the management, Samuel was asked to select a cloud service provider. After extensive research on the available public cloud service providers, Samuel made his recommendation. Within a short period, Samuel along with his team successfully transferred all applications and data to the public cloud. Samuel’s team would like to configure and maintain the platform, infrastructure, and applications in the new cloud computing environment. Which component of a cloud platform and infrastructure provides tools and interfaces to Samuel’s team for configuring and maintaining the platform, infrastructure, and application?
A. Virtualization Component
B. Computer Component
C. Physical and Environment Component
D. Management Component
Answer: D
Question #12 (Topic: Exam A)
Global InfoSec Solution Pvt. Ltd. is an IT company that develops mobile-based software and applications. For smooth, secure, and cost-effective facilitation of business, the organization uses public cloud services. Now, Global InfoSec Solution Pvt. Ltd. is encountering a vendor lock-in issue. What is vendor lock-in in cloud computing?
A. It is a situation in which a cloud consumer cannot switch to another cloud service provider without substantial switching costs
B. It is a situation in which a cloud service provider cannot switch to another cloud service broker without substantial switching costs
C. It is a situation in which a cloud consumer cannot switch to a cloud carrier without substantial switching costs
D. It is a situation in which a cloud consumer cannot switch to another cloud service broker without substantial switching costs
Answer: A
Question #13 (Topic: Exam A)
Richard Roxburgh works as a cloud security engineer in an IT company. His organization was dissatisfied with the services of its previous cloud service provider. Therefore, in January 2020, his organization adopted AWS cloud-based services and shifted all workloads and data in the AWS cloud. Richard wants to provide complete security to the hosted applications before deployment and while running in the AWS ecosystem. Which of the following automated security assessment services provided by AWS can be used by Richard to improve application security and check the application for any type of vulnerability or deviation from the best practices automatically?
A. AWS CloudFormation
B. Amazon Inspector
C. AWS Control Tower
D. Amazon CloudFront
Answer: B
Question #14 (Topic: Exam A)
GlobalCloud is a cloud service provider that offers various cloud-based secure and cost-effective services to cloud consumers. The customer base of this organization increased within a short period; thus, external auditing was performed on GlobalCloud. The auditor used spreadsheets, databases, and data analyzing software to analyze a large volume of data. Based on the given information, which cloud-based audit method was used by the auditor to collect the objective evidence?
A. CAAT
B. Re-Performance
C. Striping
D. Gap Analysis
Answer: A
Question #15 (Topic: Exam A)
Rebecca Mader has been working as a cloud security engineer in an IT company located in Detroit, Michigan. Her organization uses AWS cloud-based services. An application is launched by a developer on an EC2 instance that needs access to the S3 bucket (photos). Rebecca created a get-pics service role and attached it to the EC2 instance. This service role comprises a permission policy that allows read-only access to the S3 bucket and a trust policy that allows the instance to assume the role and retrieve temporary credentials. The application uses the temporary credentials of the role to access the photo bucket when it runs on the instance. Does the developer need to share or manage credentials or does the admin need to grant permission to the developer to access the photo bucket?
A. Yes, the developer has to share or manage credentials, but the admin does not have to grant permission to the developer to access the photo bucket
B. No, the developer never has to share or manage credentials and the admin does not have to grant permission to the developer to access the photo bucket
C. No, the developer never has to share or manage credentials, but the admin has to grant permission to the developer to access the photo bucket
D. Yes, the developer should share or manage credentials and the admin should grant permission to the developer to access the photo bucket
Answer: B