Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCloud Security Essentials

Domain 8Objective 2

Cloud Security Standards CSE Practice Questions (Page 5)

Part of the Cloud Compliance and Governance domain, which makes up ~13% of our current practice bank.

46questions here
10free pages
12concepts

Questions 21–25

  1. 21expert · hard

    A cloud service provider is implementing ISO/IEC 27017 and needs to define the responsibilities for implementing specific controls. The provider and a customer are negotiating a contract. The customer wants the provider to be responsible for implementing all controls related to the customer's data, including access controls and encryption. The provider argues that some controls are the customer's responsibility. Which of the following controls is most likely the customer's responsibility under ISO/IEC 27017?

    Select an answer first
  2. 22foundation · easy

    Which NIST publication provides guidelines on security and privacy in public cloud computing?

    Select an answer first
  3. 23expert · hard

    A company is using a public cloud SaaS application to process customer PII. The SaaS provider is ISO/IEC 27017 and ISO/IEC 27018 certified. The company's compliance officer wants to know which security controls the company is still responsible for implementing. Which of the following is the company's responsibility?

    Select an answer first
  4. 24foundation · easy

    Which of the following is a trust service criterion that focuses on the protection of information from unauthorized disclosure?

    Select an answer first
  5. 25expert · hard

    A U.S.-based health app startup stores electronic protected health information (ePHI) in a public cloud. The startup has signed a Business Associate Agreement (BAA) with the cloud provider. The startup's compliance officer wants to ensure that all ePHI is encrypted at rest and in transit, and that access is logged. The cloud provider offers encryption by default and logging, but the startup must configure its own database to use encryption. What is the most accurate statement regarding the startup's compliance with HIPAA?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.