
EC-CouncilCloud Security Essentials
Domain 7Objective 2
Risk Assessment Frameworks for Cloud Environments CSE Practice Questions (Page 1)
Part of the Cloud Security Risk Assessment and Management domain, which makes up ~13% of our current practice bank.
52questions here
11free pages
8concepts
Questions 1–5
- 1
Which domain of the CSA CCM would most likely address controls related to data encryption and key management?
Select an answer first - 2
Which of the following is a primary purpose of using a risk assessment framework in a cloud environment?
Select an answer first - 3
A company is using ISO/IEC 27005 to manage risks for its cloud email service. During the risk assessment, they identify that the risk of phishing is high. They decide to implement multi-factor authentication and employee training. What type of risk treatment option are they applying?
Select an answer first - 4
A multinational company uses a hybrid cloud environment with sensitive customer data stored in a public cloud object storage service. The risk manager wants to conduct a risk assessment following ISO/IEC 27005 and needs to ensure that risk treatment decisions are documented and reviewed periodically. Which sequence of activities aligns with ISO/IEC 27005?
Select an answer first - 5
What is the primary purpose of the CSA Cloud Controls Matrix (CCM)?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.