
EC-CouncilCloud Security Essentials
Domain 7Objective 1
Identifying Cloud Security Risks CSE Practice Questions (Page 5)
Part of the Cloud Security Risk Assessment and Management domain, which makes up ~13% of our current practice bank.
45questions here
9free pages
7concepts
Questions 21–25
- 21
A risk analyst is identifying risks for a new cloud service. The analyst has limited time and must choose between conducting interviews with the provider's security team and sending a detailed questionnaire. The provider has been responsive in the past, but the questionnaire may take weeks to be returned. Which approach is most appropriate?
Select an answer first - 22
Which of the following is an automated tool commonly used to identify cloud security risks?
Select an answer first - 23
A company has a large amount of data in cloud storage, including public marketing files, internal project plans, and customer PII. The security team must classify the data to prioritize risk assessment. The company has a limited budget and cannot assess all data at the same level. What is the most effective classification strategy?
Select an answer first - 24
A company is moving its customer relationship management (CRM) system to a public cloud. The CRM contains sensitive customer data. The security team is identifying risks related to shared responsibility. Which risk is most directly associated with the shared responsibility model?
Select an answer first - 25
A company uses a cloud-based customer relationship management (CRM) service. The CRM provider recently announced a change in its data retention policy, and the company's security team is concerned about potential exposure of customer data. The company has no direct control over the CRM's underlying infrastructure. Which risk source should the security team prioritize in their risk identification process?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.