
EC-CouncilCloud Security Essentials
Domain 8Objective 3
Cloud Security Governance and Risk Management CSE Practice Questions (Page 2)
Part of the Cloud Compliance and Governance domain, which makes up ~13% of our current practice bank.
49questions here
10free pages
8concepts
Questions 6–10
- 6
A company is evaluating a new cloud service that will process sensitive financial data. The risk assessment reveals a high likelihood of a data breach due to the service's immature security controls. The company's risk appetite is moderate. Which combination of strategies is most appropriate?
Select an answer first - 7
A company has implemented a cloud security governance framework. To ensure the framework remains effective, the security team wants to establish a process for continuous improvement. Which activity is most aligned with continuous improvement?
Select an answer first - 8
A company is implementing a cloud risk management process. After identifying and assessing risks, the team implements controls. What is the next step in the risk management process?
Select an answer first - 9
A company is evaluating two risk mitigation options for a critical cloud application. Option 1 costs $50,000 per year and reduces the annualized loss expectancy (ALE) from $200,000 to $20,000. Option 2 costs $30,000 per year and reduces the ALE from $200,000 to $60,000. The company has a limited budget and wants to maximize risk reduction per dollar spent. Which option should the company choose?
Select an answer first - 10
Which compliance framework is specifically designed for organizations that handle credit card information?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.