
Certified Cloud Security Professional
Domain 6Objective 4
Understand Implications of Cloud to Enterprise Risk Management CCSP Practice Questions (Page 5)
Part of the Legal, Risk and Compliance domain, which accounts for 13% of the CCSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~9–16 in this domain), expect 2–3 from this objective — we provide 23 practice questions to prepare you well beyond it. (estimate)
23questions here
5free pages
7concepts
13%of the exam
Questions 21–23
- 21
A company is migrating a legacy application to the cloud. The application has a known critical vulnerability that cannot be patched easily. The company decides to implement a web application firewall (WAF) in front of the application to reduce the likelihood of exploitation. Which risk treatment strategy is the company applying?
Select an answer first - 22
Which risk management framework is specifically designed for federal agencies and includes a structured process for categorizing, selecting, implementing, and assessing security controls?
Select an answer first - 23
In a cloud environment, which role is primarily responsible for determining the purpose and means of processing personal data?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CCSP
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CCSP” is a trademark of its owner, used for identification only.