Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCloud Security Essentials

Domain 7Objective 2

Risk Assessment Frameworks for Cloud Environments CSE Practice Questions (Page 3)

Part of the Cloud Security Risk Assessment and Management domain, which makes up ~13% of our current practice bank.

52questions here
11free pages
8concepts

Questions 11–15

  1. 11application · medium

    A healthcare startup is migrating its patient-facing web application to AWS. The company must comply with HIPAA and wants to use a risk framework that provides a comprehensive set of cloud-specific security controls mapped to compliance requirements. The security team has limited experience with formal risk management and needs a framework that can be used as a baseline for both risk assessment and continuous compliance monitoring. Which framework should they choose?

    Select an answer first
  2. 12expert · hard

    A security analyst is using the FAIR model to quantify the risk of a ransomware attack on a cloud storage service. They have estimated that the annualized loss expectancy (ALE) is $500,000. However, the analyst is uncertain about the probability of a breach. What is the best way to handle this uncertainty in the FAIR analysis?

    Select an answer first
  3. 13foundation · easy

    When applying a risk assessment framework to a cloud environment, which activity is most aligned with the customer's responsibility in the shared responsibility model?

    Select an answer first
  4. 14application · medium

    A healthcare organization is migrating a patient-facing application to a public cloud IaaS environment. The compliance team must demonstrate alignment with HIPAA security requirements to auditors. The organization has no existing risk framework in place and needs a structured way to map cloud-specific controls to HIPAA requirements while clarifying which security controls are the cloud provider's responsibility. Which approach best meets these needs?

    Select an answer first
  5. 15foundation · easy

    In the cloud shared responsibility model, which party is typically responsible for managing risks associated with the physical security of data centers?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.