CCSE Cloud Risk & Compliance Management 2 — Questions and Answers
Question 1: Which risk treatment option involves transferring cloud security risk to a third party such as a cyber insurance provider?
- Risk avoidance
- Risk acceptance
- Risk transference (Correct answer)
- Risk mitigation
Correct answer: Risk transference
Risk transference shifts the financial impact of a risk to a third party, such as purchasing cyber liability insurance.
Question 2: An organization discovers that its cloud provider stores backups in a jurisdiction with weak privacy laws. Which compliance concern does this primarily raise?
- Data residency and sovereignty (Correct answer)
- Service-level agreement breach
- Encryption key management
- Vendor lock-in risk
Correct answer: Data residency and sovereignty
Data residency and sovereignty laws require data to remain within specific geographic boundaries with appropriate legal protections.
Question 3: What is the primary purpose of a Cloud Security Alliance (CSA) STAR certification for a cloud provider?
- Proof of GDPR compliance
- Transparent assurance of cloud security controls (Correct answer)
- PCI DSS Level 1 attestation
- ISO 27001 replacement
Correct answer: Transparent assurance of cloud security controls
CSA STAR certification provides transparent, publicly accessible assurance of a cloud provider's security controls based on the Cloud Controls Matrix.
Question 4: Under the shared responsibility model, which security function remains ALWAYS the customer's responsibility regardless of service model (IaaS, PaaS, SaaS)?
- Hypervisor patching
- Physical data center security
- Identity and access management for user accounts (Correct answer)
- Network infrastructure management
Correct answer: Identity and access management for user accounts
Identity and access management for end-user accounts is always the customer's responsibility across all cloud service models.
Question 5: A risk register entry shows a vulnerability with high likelihood but low impact. What is the recommended initial response?
- Immediately escalate to executive leadership
- Accept the risk without further action
- Monitor and implement low-cost controls (Correct answer)
- Transfer the risk to cyber insurance
Correct answer: Monitor and implement low-cost controls
High-likelihood, low-impact risks are typically managed with cost-effective monitoring and lightweight controls rather than escalation or full transfer.
Question 6: Which framework maps cloud security controls specifically to compliance requirements from PCI DSS, HIPAA, GDPR, and other regulations?
- NIST SP 800-53
- CSA Cloud Controls Matrix (CCM) (Correct answer)
- CIS Benchmarks
- COBIT 2019
Correct answer: CSA Cloud Controls Matrix (CCM)
The CSA Cloud Controls Matrix maps cloud security controls to multiple compliance frameworks and industry standards in a single reference document.
Question 7: What does a Residual Risk represent after security controls have been applied?
- The original inherent risk before any controls
- The risk level that remains after applying mitigation controls (Correct answer)
- Risks that have been transferred to third parties
- Risks accepted without any treatment
Correct answer: The risk level that remains after applying mitigation controls
Residual risk is the remaining level of risk after controls have been applied to reduce the inherent risk.
Which risk treatment option involves transferring cloud security risk to a third party such as a cyber insurance provider?