Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCloud Security Essentials

Domain 7Objective 2

Risk Assessment Frameworks for Cloud Environments CSE Practice Questions (Page 10)

Part of the Cloud Security Risk Assessment and Management domain, which makes up ~13% of our current practice bank.

52questions here
11free pages
8concepts

Questions 46–50

  1. 46application · medium

    A company has implemented a risk management process based on NIST RMF for its cloud environment. The security team wants to ensure that risks are continuously monitored and that controls remain effective as the cloud environment changes. Which activity is most aligned with the 'Monitor' step of NIST RMF?

    Select an answer first
  2. 47expert · hard

    A company is deciding between two cloud security investments: one that reduces the likelihood of a data breach and another that reduces the impact of a breach. The CISO wants to use the FAIR model to determine which investment provides the greater risk reduction per dollar spent. What is the most appropriate way to use FAIR for this decision?

    Select an answer first
  3. 48application · medium

    A company uses a public cloud IaaS environment where the cloud provider manages the hypervisor and physical network, while the customer manages the virtual machines and applications. During a risk assessment using NIST RMF, the team must assign responsibility for implementing a control that restricts network access to the virtual machines. Who is responsible for implementing this control?

    Select an answer first
  4. 49expert · hard

    A company is evaluating risk assessment frameworks for a new cloud initiative. They need to choose between NIST RMF, ISO/IEC 27005, CSA CCM, and FAIR. The company has a strong compliance focus and needs to demonstrate due diligence to regulators, but also wants to quantify risks in financial terms for the board. Which combination of frameworks is most appropriate?

    Select an answer first
  5. 50foundation · easy

    Which ISO/IEC 27005 activity involves estimating the likelihood and impact of a risk event on a cloud-based information asset?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.