
EC-CouncilCloud Security Essentials
Domain 7Objective 5
Cloud Risk Treatment, Response, and Mitigation CSE Practice Questions (Page 2)
Part of the Cloud Security Risk Assessment and Management domain, which makes up ~13% of our current practice bank.
46questions here
10free pages
8concepts
Questions 6–10
- 6
A company has implemented a risk treatment plan that includes new security controls. Six months later, the company undergoes a major cloud migration that changes the architecture. What should the company do to ensure the risk treatment remains effective?
Select an answer first - 7
A company's risk assessment identifies a risk with a low likelihood and low impact. The cost to mitigate the risk is higher than the potential loss. The company's risk acceptance criteria require that all accepted risks be reviewed annually. What should the company do?
Select an answer first - 8
A cloud security team wants to reduce the risk of unauthorized access to a cloud storage bucket. They implement a policy that requires multi-factor authentication (MFA) for all users who access the bucket. Which type of security control does this represent?
Select an answer first - 9
A company has completed a risk assessment and identified a residual risk of a data breach due to a legacy system that cannot be patched. The risk is rated as low likelihood and medium impact. The company's risk appetite statement says that risks with a potential financial impact below $50,000 are acceptable, but risks above that threshold require executive approval. The estimated impact of a breach is $30,000. The CISO wants to formally accept this risk. What is the correct course of action?
Select an answer first - 10
After implementing risk treatment measures, an organization assesses the risk that remains. What is this remaining risk called?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.