
EC-CouncilCloud Security Essentials
Domain 8Objective 3
Cloud Security Governance and Risk Management CSE Practice Questions (Page 9)
Part of the Cloud Compliance and Governance domain, which makes up ~13% of our current practice bank.
49questions here
10free pages
8concepts
Questions 41–45
- 41
In the cloud risk management process, what is the primary purpose of the risk assessment step?
Select an answer first - 42
A company is performing a risk assessment for a new cloud application. The risk team has identified that a data breach could cost $1 million, and the likelihood of a breach is estimated at 10% per year. What is the annualized loss expectancy (ALE) for this risk?
Select an answer first - 43
In the shared responsibility model, which of the following is typically the responsibility of the cloud customer?
Select an answer first - 44
A company uses a SaaS HR platform that stores employee personal data. The company is the data controller. A data breach occurs due to a vulnerability in the SaaS provider's application. Which party is responsible for notifying the regulatory authority?
Select an answer first - 45
A company is subject to both GDPR and PCI DSS. They are designing a new cloud application that will store both personal data and cardholder data. Which approach best ensures compliance with both regulations?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.