Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCloud Security Essentials

Domain 7Objective 2

Risk Assessment Frameworks for Cloud Environments CSE Practice Questions (Page 4)

Part of the Cloud Security Risk Assessment and Management domain, which makes up ~13% of our current practice bank.

52questions here
11free pages
8concepts

Questions 16–20

  1. 16expert · hard

    A company is using ISO/IEC 27005 for risk management in a multi-cloud environment. They have identified a risk that is currently treated by accepting it, but the risk level has increased due to new regulatory requirements. What should the company do according to ISO/IEC 27005?

    Select an answer first
  2. 17application · medium

    A startup is building a cloud-native application on a public cloud and needs a lightweight risk assessment process that can be integrated into their DevOps pipeline. They want to identify risks early and continuously, without a heavy compliance burden. Which framework is most suitable for this agile environment?

    Select an answer first
  3. 18expert · hard

    A company is using NIST RMF to assess risks for a workload deployed on a public cloud IaaS platform. During the 'Assess' step, they find that the cloud provider has implemented physical security controls, but the customer is responsible for patching the operating system. How should the risk assessment document this?

    Select an answer first
  4. 19application · medium

    A government contractor is moving a workload to a public cloud and must apply the NIST RMF. During the 'Select' step, the team identifies a set of baseline controls. However, they realize that some controls are inherited from the cloud provider and others must be implemented by the customer. What is the most appropriate action to clarify control ownership and ensure the RMF process is correctly applied?

    Select an answer first
  5. 20foundation · easy

    In the NIST Risk Management Framework (RMF), which step involves selecting and implementing security controls to mitigate identified risks?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.