
Certified Cloud Security Professional
Domain 6Objective 4
Understand Implications of Cloud to Enterprise Risk Management CCSP Practice Questions (Page 3)
Part of the Legal, Risk and Compliance domain, which accounts for 13% of the CCSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~9–16 in this domain), expect 2–3 from this objective — we provide 23 practice questions to prepare you well beyond it. (estimate)
23questions here
5free pages
7concepts
13%of the exam
Questions 11–15
- 11
Which dimension of the risk environment in cloud computing includes risks related to the physical data center and network infrastructure?
Select an answer first - 12
Which of the following is a key component to examine when evaluating a cloud provider's risk management program?
Select an answer first - 13
Which metric would be most appropriate to measure the effectiveness of a cloud security control, such as the percentage of systems with patching completed on time?
Select an answer first - 14
A company is required to comply with both ISO 31000 and NIST RMF for its cloud risk management. The company finds that the two frameworks have different processes and terminology. What is the best approach to reconcile these frameworks?
Select an answer first - 15
Which regulatory framework requires public companies to maintain internal controls over financial reporting, which may include controls over cloud-based financial systems?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CCSP” is a trademark of its owner, used for identification only.