
EC-CouncilCloud Security Essentials
Domain 7Objective 5
Cloud Risk Treatment, Response, and Mitigation CSE Practice Questions (Page 7)
Part of the Cloud Security Risk Assessment and Management domain, which makes up ~13% of our current practice bank.
46questions here
10free pages
8concepts
Questions 31–35
- 31
A company has implemented a risk treatment plan that includes encryption and access controls for a sensitive database. The residual risk is rated as low, which is within the company's risk appetite. However, the company's risk monitoring program detects that a new type of attack could bypass the access controls. What should the company do?
Select an answer first - 32
An organization has implemented security controls to reduce a risk. The remaining risk is still above the organization's risk appetite. What should the organization do next?
Select an answer first - 33
A company has a risk treatment plan that includes quarterly vulnerability scans. After a major cloud migration, the company notices that the scans are not covering the new environment. What should the company do?
Select an answer first - 34
A financial services company runs a customer-facing web application in a public cloud. A risk assessment identified a high-likelihood, high-impact risk of a data breach due to a known vulnerability in a third-party payment processing library. The company has a low risk appetite and cannot accept any residual risk that could lead to a breach. The vulnerability cannot be patched because the vendor has not released a fix. What is the most appropriate risk treatment option?
Select an answer first - 35
A company uses a cloud-based database that stores financial data. The risk assessment identified a risk of unauthorized data modification by a malicious insider. The company wants to implement a detective control to detect such activity. Which control should be implemented?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.