
EC-CouncilCertified Cloud Security Engineer
Domain 1Objective 3
Standards, Policies, and Legal Issues in Cloud CCSE Practice Questions (Page 5)
Part of the Cloud Security Fundamentals and Governance domain, which makes up ~25% of our current practice bank.
44questions here
9free pages
8concepts
Questions 21–25
- 21
A security auditor is conducting a compliance audit for a company that uses a cloud provider. The company has a contract with the provider that includes a right-to-audit clause. The provider's data centers are located in multiple countries. The auditor needs to verify the provider's security controls. Which action should the auditor take?
Select an answer first - 22
A cloud customer is planning an audit of a SaaS provider that hosts customer data. The provider has ISO/IEC 27017 certification and offers a shared responsibility matrix. The customer's audit team wants to verify that the provider's controls are effective and that the customer's own responsibilities are clearly defined. Which audit approach is most appropriate?
Select an answer first - 23
A cloud customer is evaluating a new SaaS provider that will process personal data on behalf of the customer. The customer wants to verify that the provider has implemented cloud-specific security controls and also provides transparency about data processing. Which combination of certifications/attestations would best address both concerns?
Select an answer first - 24
Which legal concept refers to the requirement that data is subject to the laws of the country or region where it is physically stored or processed?
Select an answer first - 25
A cloud customer is planning an audit of its own use of a cloud provider. The customer wants to verify that its data handling practices comply with GDPR. Which audit activity is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCSE” is a trademark of its owner, used for identification only.