EC-COUNCIL · 312-40

EC-Council 312-40 CCSE Exam Practice Questions

147 questionsPDF by emailUpdated September 2026

US$39

Try 10 questions free

Card, Apple Pay or Google Pay. Your PDF is sent by email as soon as you check out.

Pass or your money backFail the exam after using this pack and we refund it. How the guarantee works
Category:
TRY BEFORE YOU BUY

Three of the 147 questions in this pack

Question 1

Lexie Roth works as a cloud security engineer in an IT company located in Boston, Massachusetts. Her organization generates a huge amount of data. To increase the storage size, speed, and fault tolerance, Lexie would like to configure and create a RAID. Therefore, she created a RAID on Windows Server 2016, which includes block- level striping with a distributed parity. The parity information is distributed among all drives, except one. The data chunks in the RAID are larger than the regular I/O size, but they can be re-sized. To prevent data loss after a drive fails, data are calculated from the distributed parity. The RAID configured by Lexie requires at least three disks, but for robust performance, Lexie used seven disks. Based on the given information, which of the following RAID was configured and created by Lexie?

  1. RAID 3
  2. RAID 5
  3. RAID 1
  4. RAID 0
Show answer and explanation

Correct answer: B. RAID 5

RAID 5 uses block-level striping with distributed parity across all drives, where parity information is spread among all disks except one. It requires a minimum of three drives and can recover from a single drive failure using the distributed parity. The stripe size (data chunks) is configurable. Lexie's seven-disk configuration with these exact characteristics describes RAID 5.

Why the other options are wrong

  • A. RAID 3 uses byte-level striping with a dedicated parity drive, not distributed parity across all drives.
  • C. RAID 1 is mirroring without striping and does not use distributed parity.
  • D. RAID 0 is striping without parity and provides no fault tolerance or data recovery capability.

Question 2

Cindy Williams has been working as a cloud security engineer in an IT company situated in Austin, Texas. Owing to the robust security and cost-effective features provided by AWS, her organization adopted AWS cloud-based services. Cindy has deployed an application in the Amazon Elastic Compute Cloud (EC2) instance.

Which of the following cloud computing service model does the Amazon EC2 instance represent?

  1. SaaS
  2. DaaS
  3. PaaS
  4. IaaS
Show answer and explanation

Correct answer: D. IaaS

Amazon EC2 provides virtual computing resources where users can deploy applications on virtualized hardware infrastructure. IaaS (Infrastructure-as-a-Service) is the model where the cloud provider manages virtualization, storage, and networking while the customer manages the operating system, middleware, and applications. EC2 exemplifies this model by providing compute infrastructure on demand.

Why the other options are wrong

  • A. SaaS delivers complete applications over the internet; EC2 provides infrastructure, not finished applications.
  • B. DaaS (Desktop-as-a-Service) delivers virtual desktop environments; EC2 provides compute instances for various uses.
  • C. PaaS provides a platform with pre-configured services for development; EC2 is raw infrastructure requiring more customer management.

Question 3

Billy Pratt works as a cloud security engineer in an MNC. In 2012, his organization transferred all applications and data into an AWS cloud environment. Billy would like to analyze, investigate, and identify the root cause of malicious activities in his organization’s AWS cloud environment.

Which of the following Amazon services automatically collects data from various AWS resources and utilizes machine learning, statistical analysis, and graph theory to provide a unified and interactive view of resources and users that would help Billy in determining the root cause of suspicious activities?

  1. Amazon Inspector
  2. Amazon Detective
  3. Amazon GuardDuty
  4. Amazon Macie
Show answer and explanation

Correct answer: B. Amazon Detective

Amazon Detective automatically collects data from AWS resources including VPC Flow Logs, CloudTrail, and GuardDuty findings. It applies machine learning, statistical analysis, and graph theory to analyze relationships between resources and users, providing visualization of suspicious activities and helping determine root causes of security incidents.

Why the other options are wrong

  • A. Amazon Inspector performs vulnerability assessments on EC2 instances and applications; it does not investigate existing malicious activities.
  • C. Amazon GuardDuty detects threats and generates findings but does not provide the investigative analysis and root cause determination that Detective offers.
  • D. Amazon Macie discovers and protects sensitive data; it does not investigate malicious activities or provide root cause analysis.

See all 10 free questions Get the full pack, US$39

147 practice questions for EC-Council Certified Cloud Security Engineer (CCSE), exam 312-40, with full explanations.

Every question comes with the correct answer, the reasoning behind it, and a short note on why each wrong option is wrong. Work through it once with the answers, then again with the questions-only copy under exam conditions.

  • 147 questions mapped to the CCSE exam blueprint
  • Answers and explanations for every question, including the wrong options
  • A questions-only PDF for timed practice runs
  • Instant delivery by email the moment you check out
  • Free monthly updates for as long as the exam is live
  • Pass or your money back

A 312-40 attempt costs US$550. This pack is US$39, paid once.

Try 10 questions free before you buy.

Last updated September 2026 · 147 questions

What makes the CCSE hard

CCSE is the multi-cloud security exam that CCSP is not: where CCSP stays vendor-neutral, CCSE expects candidates to know how the same control is implemented in AWS, Azure and Google Cloud. 125 questions in four hours is a long sitting, and the questions move between conceptual and hands-on, so both what a CSPM does and which service provides it on each platform need to be known.

The blueprint runs through eleven modules: cloud security fundamentals, platform and infrastructure security, application security including container and serverless security, data security with KMS and HSM, operations security with IAM, logging and CSPM, penetration testing in the cloud, incident detection and response, forensics, business continuity and disaster recovery, governance, risk and compliance, and standards, policies and legal issues.

The passing score is set per exam form, with 70% the usual quoted figure and the range running from 60% to 78%.

About the exam

312-40 (Certified Cloud Security Engineer) earns the EC-Council CCSE certification. It covers cloud security fundamentals, platform and infrastructure security, application security, data security, operations security, cloud penetration testing, incident detection and response, forensics, business continuity and disaster recovery, governance, risk and compliance, and standards, policies and legal issues across AWS, Azure and Google Cloud. There are no prerequisites with official training; self-study candidates need two years of information security experience and an eligibility application.

Exam modules

  • Introduction to cloud security
  • Platform and infrastructure security in the cloud
  • Application security in the cloud
  • Data security in the cloud
  • Operations security in the cloud
  • Penetration testing in the cloud
  • Incident detection and response in the cloud
  • Forensics investigation in the cloud
  • Business continuity and disaster recovery in the cloud
  • Governance, risk management and compliance in the cloud
  • Standards, policies and legal issues in the cloud

125 multiple choice questions, 240 minutes, passing score set per exam form (typically 70%), US$550 per attempt, ECC Exam Portal with remote proctoring, certification valid for three years with EC-Council continuing education.

Reviews

There are no reviews yet.

Only logged in customers who have purchased this product may leave a review.

Questions before you buy

What do I get when I buy the EC-Council 312-40 CCSE pack?

147 practice questions as a PDF, each with the correct answer, a full explanation and a note on why the other options are wrong, plus a separate questions-only PDF for timed practice.

How quickly do I receive it?

Your PDF is prepared and sent to your email address after checkout, and you get a confirmation as soon as it is on its way.

Is there a free sample?

Yes. Ten questions from this pack, with answers and explanations, are free on this page and as a PDF, so you can judge the quality before you pay.

Are updates included?

Yes. The pack is updated every month for as long as the exam is live, and updates are free for everyone who has bought it.

What if I fail the exam?

We refund the pack. Sit the exam 7 to 30 days after buying, then send your official score report within 7 days of the exam date, as set out in the refund policy.

Can I share it with colleagues?

Each purchase is licensed to one person. For a team, school or training organisation, email support@certstash.com for a licence that fits.