
EC-CouncilCloud Security Essentials
Domain 7Objective 5
Cloud Risk Treatment, Response, and Mitigation CSE Practice Questions (Page 8)
Part of the Cloud Security Risk Assessment and Management domain, which makes up ~13% of our current practice bank.
46questions here
10free pages
8concepts
Questions 36–40
- 36
A company is considering outsourcing its email security to a cloud-based email filtering service. The company wants to transfer the risk of email-borne malware. Which factor is most important to evaluate when determining the effectiveness of this risk transfer?
Select an answer first - 37
A company has implemented a risk treatment plan that includes new security controls. The CISO wants to ensure that the controls remain effective over time. Which ongoing activity should be established?
Select an answer first - 38
An organization determines that the cost of implementing strong encryption for a low-impact dataset exceeds the potential loss from a data breach. The organization decides to proceed without additional controls and formally documents this decision. Which risk treatment option is being applied?
Select an answer first - 39
A company runs a critical application in the cloud and wants to reduce the financial impact of a potential service outage. The company has already implemented high-availability architecture but wants to further reduce the residual financial risk. Which risk transfer mechanism would be most effective?
Select an answer first - 40
A company's risk assessment shows that a legacy application has a high likelihood of being exploited due to unpatched vulnerabilities. The application is critical to operations and cannot be taken offline. The organization has a moderate risk appetite and limited security staff. Which combination of treatment actions should be prioritized in the risk response plan?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.