
EC-CouncilCloud Security Essentials
Domain 7Objective 2
Risk Assessment Frameworks for Cloud Environments CSE Practice Questions (Page 2)
Part of the Cloud Security Risk Assessment and Management domain, which makes up ~13% of our current practice bank.
52questions here
11free pages
8concepts
Questions 6–10
- 6
A financial services firm is evaluating the risk of a data breach in its cloud environment. The CISO wants to express risk in monetary terms to justify security investments to the board. The team has historical data on breach frequency and estimated loss per event. They also need to account for uncertainty in their estimates. Which framework is best suited for this quantitative risk analysis?
Select an answer first - 7
According to ISO/IEC 27005, which phase of risk management involves deciding whether to accept, avoid, transfer, or mitigate a risk?
Select an answer first - 8
A federal agency is required to use NIST RMF for its cloud systems. During the 'Categorize' step, the system is determined to have a high impact level. The team is now selecting controls. What is the primary consideration when selecting controls in a cloud environment?
Select an answer first - 9
A large enterprise is moving to a hybrid cloud model and must comply with multiple regulations. They need a risk framework that can be applied consistently across on-premises and cloud environments, and they also want to quantify risks in financial terms for board reporting. Which combination of frameworks would best meet these needs?
Select an answer first - 10
A company is using NIST RMF to assess a workload on a PaaS platform. The provider manages the runtime environment, but the customer is responsible for the application code and data. During the risk assessment, the team needs to determine who is responsible for patching the application framework. What is the correct approach?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.