Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCloud Security Essentials

Domain 8Objective 2

Cloud Security Standards CSE Practice Questions (Page 8)

Part of the Cloud Compliance and Governance domain, which makes up ~13% of our current practice bank.

46questions here
10free pages
12concepts

Questions 36–40

  1. 36application · medium

    A cloud service provider is seeking FedRAMP authorization for its SaaS offering. The provider has implemented security controls based on NIST SP 800-53. What is the primary purpose of the FedRAMP authorization process for the provider?

    Select an answer first
  2. 37application · medium

    A cloud service provider wants to sell its SaaS offering to multiple U.S. federal agencies. To avoid each agency conducting its own separate security assessment, the provider wants a single authorization that can be reused. Which program should the provider pursue?

    Select an answer first
  3. 38foundation · easy

    Which of the following best describes how the CSA CCM can be used?

    Select an answer first
  4. 39foundation · easy

    In a cloud environment, who is typically responsible for securing the hypervisor under the PCI DSS shared responsibility model?

    Select an answer first
  5. 40expert · hard

    A security auditor is using the CSA Cloud Controls Matrix (CCM) to assess a cloud provider's controls. The auditor needs to map the provider's controls to both SOC 2 Trust Services Criteria and ISO/IEC 27001. The auditor finds that a specific control in the CCM maps to multiple criteria in both frameworks. What is the most efficient way for the auditor to document this mapping?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.