
EC-CouncilCloud Security Essentials
Domain 7Objective 2
Risk Assessment Frameworks for Cloud Environments CSE Practice Questions (Page 8)
Part of the Cloud Security Risk Assessment and Management domain, which makes up ~13% of our current practice bank.
52questions here
11free pages
8concepts
Questions 36–40
- 36
Which factor in the FAIR model represents the probability that a threat event will occur?
Select an answer first - 37
A risk analyst is using the FAIR model to compare two cloud security investments. Investment A reduces the likelihood of a breach by 50%, while Investment B reduces the impact by 50%. The current annualized loss expectancy (ALE) is $1,000,000. Which investment should be prioritized if the goal is to minimize the ALE?
Select an answer first - 38
A government contractor is moving a workload to a public cloud and must comply with FedRAMP requirements. The organization needs a risk assessment framework that is already mapped to FedRAMP and can help demonstrate compliance to the Joint Authorization Board. Which framework is the best choice?
Select an answer first - 39
An organization operating in a highly regulated industry needs to demonstrate compliance with multiple standards. Which framework would be most suitable for mapping cloud controls to various compliance requirements?
Select an answer first - 40
Which NIST RMF step is primarily concerned with determining the impact level of a cloud system based on confidentiality, integrity, and availability?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.