
EC-CouncilCertified Cloud Security Engineer
Domain 1Objective 2
Governance, Risk Management, and Compliance (GRC) in Cloud CCSE Practice Questions (Page 3)
Part of the Cloud Security Fundamentals and Governance domain, which makes up ~25% of our current practice bank.
54questions here
11free pages
8concepts
Questions 11–15
- 11
A company has implemented continuous compliance monitoring in its cloud environment. The monitoring system uses a policy-as-code approach to automatically remediate non-compliant resources. However, the company has experienced an incident where a critical resource was automatically terminated because it was misconfigured. The company wants to avoid such incidents while maintaining continuous compliance. Which change should the company make?
Select an answer first - 12
A company has implemented continuous compliance monitoring in its cloud environment using a combination of native cloud services and third-party tools. The monitoring system currently checks for misconfigurations and generates alerts, but the company's security team is struggling to prioritize remediation efforts because the alerts are not linked to business impact. The compliance officer wants to improve the monitoring program to focus on the most critical risks. Which enhancement should the team implement?
Select an answer first - 13
A multinational company is using a public cloud provider with data centers in several countries. The company's data protection officer (DPO) is concerned about the legal implications of data transfers between countries. The company has customers in the EU and the US. Which action should the DPO take to address these concerns?
Select an answer first - 14
An organization has implemented continuous compliance monitoring using a CSPM tool. However, the security team is overwhelmed by alerts, many of which are false positives. They want to reduce alert fatigue while maintaining effective monitoring. Which strategy is most effective?
Select an answer first - 15
A company is evaluating compliance frameworks for its cloud environment. The company needs to demonstrate to customers that it has implemented appropriate security controls and is willing to undergo independent audits. The company is considering both ISO 27001 and SOC 2. Which factor should the company consider when choosing between the two?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCSE” is a trademark of its owner, used for identification only.