ExamDumpster

Free 312-40 sample questions

Real questions from the Certified Cloud Security Engineer (CCSE v2) practice bank, with the correct answer and an explanation for each one. No junk, no filler.

Try them in the simulator Same questions, with study, timed and flashcard modes.

Showing 10 of 20 free sample questions.

Question 1Choose one

A global logistics firm uses a multi-cloud strategy with applications deployed across AWS and Azure. To standardize security monitoring, they are forwarding all logs to a central SIEM. An analyst observes that Azure Activity Logs are being ingested successfully, but AWS CloudTrail logs are not appearing. The AWS environment uses multiple accounts under AWS Organizations, and logs are centrally collected in an S3 bucket in the management account. What is the MOST likely cause of this issue?

Question 2Choose 2

A development team is building a cloud-native application on Google Cloud Platform (GCP) and needs to manage application secrets such as API keys and database credentials. A security architect wants to ensure that secrets are not hardcoded in source code and that access is tightly controlled and audited. Which TWO GCP services should be used together to meet these requirements? (Select TWO).

Question 3Choose one

A healthcare startup is deploying its patient portal application in AWS. To comply with HIPAA, all data at rest must be encrypted. A cloud engineer decides to use Server-Side Encryption with AWS KMS-Managed Keys (SSE-KMS) for the S3 buckets storing patient records. True or False: Under the AWS Shared Responsibility Model, AWS is solely responsible for managing the lifecycle and rotation of these KMS keys.

Question 4Choose one

A financial institution is migrating its on-premises data warehouse to the cloud and has chosen Azure Synapse Analytics. Due to strict regulatory requirements, the security team must ensure that data is encrypted at rest, in transit, and that network access to the Synapse workspace is restricted to a private network. Additionally, they need to prevent data exfiltration by blocking public internet access from the workspace's managed virtual network. Which combination of Azure security features provides the most comprehensive solution to meet all these requirements?

Question 5Choose one

A retail company has deployed a large-scale e-commerce platform on AWS, using a combination of EC2 instances for the frontend, ECS containers for microservices, and RDS for the database. During a routine audit, the security team is tasked with automating the assessment of hosts for vulnerabilities and unintended network exposure. The solution must be automated, continuously assess the environment, and provide prioritized findings. Which AWS service is specifically designed for this purpose?

Question 6Choose one

During a penetration test of a cloud environment, an ethical hacker gains access to an EC2 instance with an attached IAM role. The tester wants to determine the permissions associated with this role to identify potential privilege escalation paths. Which AWS CLI command should the tester use to retrieve the policies attached to the IAM role from the compromised instance?

Question 7Choose one

A company is designing a disaster recovery (DR) plan for a critical application running in a single AWS Region. The application uses EC2 instances, an RDS database, and S3 for storing static assets. The business requires a Recovery Time Objective (RTO) of less than 1 hour and a Recovery Point Objective (RPO) of 15 minutes. The DR strategy must be cost-effective. Which DR strategy BEST meets these requirements?

Question 8Choose one

A security analyst is investigating a suspected data breach in their company's AWS environment. They believe an S3 bucket containing sensitive customer data was made public for a short period. To confirm this, the analyst needs to find evidence of `PutBucketAcl` API calls that changed the bucket's permissions. Which log source should the analyst investigate to find this specific information?

Question 9Choose one

A government agency is deploying a sensitive application on Azure and must comply with the NIST Risk Management Framework (RMF). The agency needs a tool to define and enforce organizational standards, assess compliance at scale, and remediate non-compliant resources. Which Azure service is designed to create, assign, and manage policies that enforce these rules over resources?

Question 10Choose one

A cloud security architect needs to design a secure network architecture on AWS for a multi-tier web application. The design must adhere to the principle of least privilege and defense-in-depth. Which of the following represents the BEST implementation using AWS native security controls? graph TD subgraph VPC subgraph PublicSubnet ELB[Elastic Load Balancer] end subgraph PrivateSubnet1 Web[Web Servers] end subgraph PrivateSubnet2 App[App Servers] end subgraph PrivateSubnet3 DB[Database] end end Internet --> ELB ELB --> Web Web --> App App --> DB

10 more free samples are waiting

Create a free account to unlock the whole 312-40 sample bank, or get full access to all 232 practice questions in the simulator.

Create account