CCSE Cloud Risk & Compliance Management 4 — Questions and Answers
Question 1: Which GDPR principle requires that personal data collected for one purpose not be used for an incompatible purpose without additional consent?
- Data minimization
- Purpose limitation (Correct answer)
- Storage limitation
- Integrity and confidentiality
Correct answer: Purpose limitation
The GDPR purpose limitation principle restricts the use of personal data to the specific purpose for which it was originally collected.
Question 2: A CCSE is evaluating cloud risk using the formula: Risk = Threat × Vulnerability × Impact. Which scenario represents the highest risk?
- High threat, low vulnerability, high impact
- Low threat, high vulnerability, low impact
- High threat, high vulnerability, high impact (Correct answer)
- Medium threat, medium vulnerability, low impact
Correct answer: High threat, high vulnerability, high impact
Risk is maximized when all three factors—threat likelihood, vulnerability, and impact—are high simultaneously.
Question 3: What is the purpose of a Cloud Access Security Broker (CASB) in a compliance management program?
- To replace the cloud provider's native security tools
- To enforce security policies and provide visibility between users and cloud services (Correct answer)
- To perform penetration testing of cloud APIs
- To manage cloud billing and cost optimization
Correct answer: To enforce security policies and provide visibility between users and cloud services
A CASB sits between users and cloud services to enforce security policies, provide visibility, and ensure compliance with organizational rules.
Question 4: Under FedRAMP, what level of authorization is required for cloud systems processing Controlled Unclassified Information (CUI) with moderate risk?
- FedRAMP Low
- FedRAMP Moderate (Correct answer)
- FedRAMP High
- FedRAMP Impact Level 5
Correct answer: FedRAMP Moderate
FedRAMP Moderate authorization is designed for systems where compromise could have serious adverse effects, including most CUI systems.
Question 5: Which risk scenario best describes a 'configuration drift' compliance failure in a cloud environment?
- An attacker exploits a zero-day vulnerability in the cloud provider's hypervisor
- Resources gradually deviate from their approved secure baseline over time (Correct answer)
- An employee intentionally leaks data to a competitor
- A DDoS attack overwhelms cloud-based load balancers
Correct answer: Resources gradually deviate from their approved secure baseline over time
Configuration drift occurs when cloud resources gradually diverge from their approved secure baseline, often due to ad-hoc changes or updates.
Question 6: An organization's legal team flags that its cloud provider contract lacks a right-to-audit clause. Why is this a significant compliance risk?
- It prevents the provider from accessing customer data
- It limits the organization's ability to independently verify the provider's security controls (Correct answer)
- It violates the cloud provider's terms of service
- It prevents the organization from using multi-factor authentication
Correct answer: It limits the organization's ability to independently verify the provider's security controls
Without a right-to-audit clause, the organization cannot independently verify that the provider's security controls meet regulatory and contractual requirements.
Question 7: Which approach to compliance in cloud environments is most efficient for organizations operating under multiple regulatory frameworks simultaneously?
- Implementing separate compliance programs for each regulation
- Adopting a unified controls framework that maps to multiple regulations (Correct answer)
- Outsourcing all compliance activities to the cloud provider
- Conducting annual compliance audits for each regulation separately
Correct answer: Adopting a unified controls framework that maps to multiple regulations
A unified controls framework (such as CSA CCM) maps a single set of controls to multiple regulations, reducing duplication and audit fatigue.
Which GDPR principle requires that personal data collected for one purpose not be used for an incompatible purpose without additional consent?