
EC-CouncilCloud Security Essentials
Domain 7Objective 2
Risk Assessment Frameworks for Cloud Environments CSE Practice Questions (Page 6)
Part of the Cloud Security Risk Assessment and Management domain, which makes up ~13% of our current practice bank.
52questions here
11free pages
8concepts
Questions 26–30
- 26
A cloud service provider wants to use the CSA CCM to map its controls to multiple compliance frameworks, including PCI DSS and ISO 27001. What is the primary benefit of using the CCM for this purpose?
Select an answer first - 27
A cloud security consultant is helping a client map the CSA CCM controls to the shared responsibility model for a SaaS application. The client wants to ensure that all controls are properly assigned and that no gaps exist. Which approach is most effective?
Select an answer first - 28
A security team has implemented NIST RMF for a cloud environment and is now in the Monitor step. They have discovered that a new vulnerability in the cloud provider's service could affect their system. According to NIST RMF, what should the team do?
Select an answer first - 29
A risk analyst is using the FAIR model to quantify the risk of a ransomware attack on a cloud-based file storage service. The analyst has estimated the threat event frequency and the loss magnitude. What is the next step in the FAIR model to calculate the risk?
Select an answer first - 30
Which framework is specifically designed to help organizations assess and manage risks associated with cloud computing?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.