
Certified Cloud Security Professional
Domain 6Objective 4
Understand Implications of Cloud to Enterprise Risk Management CCSP Practice Questions (Page 2)
Part of the Legal, Risk and Compliance domain, which accounts for 13% of the CCSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~9–16 in this domain), expect 2–3 from this objective — we provide 23 practice questions to prepare you well beyond it. (estimate)
23questions here
5free pages
7concepts
13%of the exam
Questions 6–10
- 6
When assessing a cloud provider's risk management program, which of the following is the primary purpose of reviewing the provider's risk appetite statement?
Select an answer first - 7
Which role is responsible for implementing the technical safeguards that protect data in a cloud environment?
Select an answer first - 8
A cloud customer purchases cyber insurance to cover potential losses from a data breach. Which risk treatment strategy does this represent?
Select an answer first - 9
A company is evaluating two cloud providers. Provider A has a mature risk management program with extensive controls and a low risk appetite, but its services are more expensive. Provider B has a less mature program with a higher risk appetite, but its services are significantly cheaper. The company has a moderate risk appetite and is cost-sensitive. What is the most appropriate approach?
Select an answer first - 10
A cloud security team is designing a risk management dashboard. They need to include metrics that provide early warning signals of increasing risk, such as the number of unpatched critical vulnerabilities and the number of failed access control attempts. Which type of metrics should they use?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CCSP” is a trademark of its owner, used for identification only.