
EC-CouncilCloud Security Essentials
Domain 7Objective 5
Cloud Risk Treatment, Response, and Mitigation CSE Practice Questions (Page 4)
Part of the Cloud Security Risk Assessment and Management domain, which makes up ~13% of our current practice bank.
46questions here
10free pages
8concepts
Questions 16–20
- 16
A company's risk assessment identifies a low-likelihood, low-impact risk related to a non-critical internal tool. The cost to mitigate the risk exceeds the potential loss. The organization's risk appetite statement allows acceptance of risks below a defined threshold. What is the appropriate action according to formal risk acceptance criteria?
Select an answer first - 17
An organization deploys a cloud-based intrusion detection system (IDS) that generates alerts when suspicious network traffic is observed. Which category of security control does the IDS represent?
Select an answer first - 18
An organization's risk assessment identifies that a ransomware attack could cause significant downtime for its customer-facing application. The organization decides to implement a mitigation control. Which control best integrates with incident response and business continuity to reduce the impact of a ransomware attack?
Select an answer first - 19
A company has a critical application that is vulnerable to a known exploit. The vendor has not yet released a patch. The company cannot afford downtime. Which combination of controls should be implemented to reduce the risk while waiting for the patch?
Select an answer first - 20
A company's risk assessment identifies that a new cloud storage service has a high likelihood of data leakage due to misconfiguration. The company is in a regulated industry and has a low risk appetite. The security team has limited time to implement controls. Which risk response plan should be prioritized?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.