
EC-CouncilCloud Security Essentials
Domain 7Objective 5
Cloud Risk Treatment, Response, and Mitigation CSE Practice Questions (Page 1)
Part of the Cloud Security Risk Assessment and Management domain, which makes up ~13% of our current practice bank.
46questions here
10free pages
8concepts
Questions 1–5
- 1
A company has a limited security budget and must address three risks: (1) a high-likelihood, low-impact risk of phishing, (2) a low-likelihood, high-impact risk of a data center outage, and (3) a medium-likelihood, medium-impact risk of misconfigured cloud resources. The company's risk appetite is moderate. Which risk response plan best prioritizes the use of limited resources?
Select an answer first - 2
A company has a cloud-based application that is critical to business operations. The risk assessment identified a high-impact risk of a ransomware attack. The company has implemented preventive controls, but the CISO wants to ensure effective response and recovery if the attack occurs. Which additional measure is most important to integrate with the incident response plan?
Select an answer first - 3
An e-commerce company experiences a data breach that exposes customer payment information. The incident response team contains the breach and restores services. The risk assessment identifies that the root cause was a misconfigured database that was publicly accessible. Which set of controls should be implemented to address the root cause and reduce the likelihood of recurrence?
Select an answer first - 4
A financial services firm is considering outsourcing its email and collaboration services to a cloud provider. The risk assessment identifies that email data is sensitive and subject to regulatory requirements. The firm wants to transfer some risk to the provider. Which approach best aligns with the shared responsibility model to achieve effective risk transfer?
Select an answer first - 5
A company has a risk acceptance policy that states risks with a likelihood rating of 'low' and an impact rating of 'low' can be accepted by the IT manager, while higher risks require CISO approval. A risk assessment identified a risk with a likelihood of 'medium' and an impact of 'low'. What should the company do?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.