CCSE Cloud Risk & Compliance Management 3 — Questions and Answers
Question 1: Which audit report type provides the most comprehensive assurance about a cloud provider's controls by covering both design and operating effectiveness?
- SOC 1 Type I
- SOC 2 Type I
- SOC 2 Type II (Correct answer)
- SOC 3
Correct answer: SOC 2 Type II
SOC 2 Type II evaluates both the design and operating effectiveness of security controls over a period of time, providing the most comprehensive assurance.
Question 2: A healthcare organization migrates to a cloud SaaS application. Under HIPAA, what agreement must be established with the cloud provider before storing PHI?
- Service Level Agreement (SLA)
- Business Associate Agreement (BAA) (Correct answer)
- Data Processing Agreement (DPA)
- Non-Disclosure Agreement (NDA)
Correct answer: Business Associate Agreement (BAA)
HIPAA requires a Business Associate Agreement (BAA) with any vendor that handles Protected Health Information (PHI) on behalf of a covered entity.
Question 3: What is the key difference between a qualitative and quantitative risk assessment approach?
- Qualitative uses monetary values; quantitative uses risk ratings
- Quantitative uses monetary values and statistics; qualitative uses descriptive ratings (Correct answer)
- Qualitative requires more data than quantitative
- Quantitative is faster and cheaper to perform
Correct answer: Quantitative uses monetary values and statistics; qualitative uses descriptive ratings
Quantitative risk assessment uses numerical values and statistical methods (e.g., ALE), while qualitative uses descriptive categories like High/Medium/Low.
Question 4: An organization uses multiple cloud providers to avoid single points of failure. This strategy primarily addresses which risk?
- Insider threat
- Vendor lock-in and provider availability risk (Correct answer)
- Data exfiltration risk
- Misconfiguration risk
Correct answer: Vendor lock-in and provider availability risk
Multi-cloud strategies reduce vendor lock-in risk and protect against provider-specific outages or business failures.
Question 5: Which element is typically included in a cloud vendor risk assessment but NOT in an internal vulnerability scan?
- Open port analysis
- Financial stability and business continuity of the vendor (Correct answer)
- CVE severity scoring
- Password policy review
Correct answer: Financial stability and business continuity of the vendor
Vendor risk assessments evaluate third-party factors like financial stability and business continuity that internal scans cannot assess.
Question 6: The PCI DSS requirement for cloud environments mandates that cardholder data is isolated within a defined boundary. What is this boundary called?
- Security perimeter
- Cardholder Data Environment (CDE) (Correct answer)
- Demilitarized Zone (DMZ)
- Trust Zone
Correct answer: Cardholder Data Environment (CDE)
PCI DSS defines the Cardholder Data Environment (CDE) as the boundary encompassing all systems that store, process, or transmit cardholder data.
Question 7: During a cloud compliance audit, an auditor requests evidence of continuous monitoring. Which tool output best satisfies this requirement?
- A one-time penetration test report
- Cloud provider's monthly uptime report
- Automated CSPM alerts and remediation logs over a defined period (Correct answer)
- Annual vulnerability assessment results
Correct answer: Automated CSPM alerts and remediation logs over a defined period
Cloud Security Posture Management (CSPM) tools provide ongoing, automated evidence of continuous monitoring and remediation activities.
Which audit report type provides the most comprehensive assurance about a cloud provider's controls by covering both design and operating effectiveness?