Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCloud Security Essentials

Domain 7Objective 5

Cloud Risk Treatment, Response, and Mitigation CSE Practice Questions (Page 7)

Part of the Cloud Security Risk Assessment and Management domain, which makes up ~13% of our current practice bank.

46questions here
10free pages
8concepts

Questions 31–35

  1. 31expert · hard

    A company has implemented a risk treatment plan that includes encryption and access controls for a sensitive database. The residual risk is rated as low, which is within the company's risk appetite. However, the company's risk monitoring program detects that a new type of attack could bypass the access controls. What should the company do?

    Select an answer first
  2. 32foundation · easy

    An organization has implemented security controls to reduce a risk. The remaining risk is still above the organization's risk appetite. What should the organization do next?

    Select an answer first
  3. 33application · medium

    A company has a risk treatment plan that includes quarterly vulnerability scans. After a major cloud migration, the company notices that the scans are not covering the new environment. What should the company do?

    Select an answer first
  4. 34application · medium

    A financial services company runs a customer-facing web application in a public cloud. A risk assessment identified a high-likelihood, high-impact risk of a data breach due to a known vulnerability in a third-party payment processing library. The company has a low risk appetite and cannot accept any residual risk that could lead to a breach. The vulnerability cannot be patched because the vendor has not released a fix. What is the most appropriate risk treatment option?

    Select an answer first
  5. 35application · medium

    A company uses a cloud-based database that stores financial data. The risk assessment identified a risk of unauthorized data modification by a malicious insider. The company wants to implement a detective control to detect such activity. Which control should be implemented?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.