
EC-CouncilCertified Cloud Security Engineer
Domain 1Objective 2
Governance, Risk Management, and Compliance (GRC) in Cloud CCSE Practice Questions (Page 4)
Part of the Cloud Security Fundamentals and Governance domain, which makes up ~25% of our current practice bank.
54questions here
11free pages
8concepts
Questions 16–20
- 16
Which statement best describes the relationship among the three components of a GRC framework in a cloud environment?
Select an answer first - 17
A company is evaluating two cloud providers. Provider A has SOC 2 Type II and ISO 27001 certifications. Provider B has only a self-assessment questionnaire. The company handles sensitive customer data and wants to minimize compliance risk. Which provider should they choose?
Select an answer first - 18
A company is using a cloud provider that is ISO 27001 certified. The company's own security team wants to ensure that their use of the cloud services complies with the company's internal security policies. What should they do?
Select an answer first - 19
A cloud security team is preparing for an external audit of its cloud environment. The auditor has requested evidence of access reviews, change management, and incident response. The team needs to provide this evidence in a way that is organized and easy for the auditor to review. Which approach should the team take?
Select an answer first - 20
Which statement accurately describes a compliance requirement in a cloud environment?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCSE” is a trademark of its owner, used for identification only.