CCSE Cloud Risk & Compliance Management 5 — Questions and Answers
Question 1: What is the primary goal of a Business Impact Analysis (BIA) in cloud risk management?
- To identify all known vulnerabilities in cloud infrastructure
- To determine the criticality of business functions and acceptable recovery timeframes (Correct answer)
- To assess the financial cost of cloud provider services
- To audit compliance with GDPR requirements
Correct answer: To determine the criticality of business functions and acceptable recovery timeframes
A BIA identifies critical business functions, their dependencies, and acceptable RTO/RPO to prioritize recovery efforts after a disruption.
Question 2: A cloud security engineer discovers that a third-party SaaS vendor has suffered a data breach affecting shared customer data. Under GDPR, what is the maximum time the data controller has to notify the supervisory authority?
- 24 hours
- 48 hours
- 72 hours (Correct answer)
- 7 days
Correct answer: 72 hours
GDPR Article 33 requires data controllers to notify the relevant supervisory authority of a personal data breach within 72 hours of becoming aware of it.
Question 3: Which cloud risk management practice involves simulating the failure of cloud dependencies to evaluate resilience before an actual incident occurs?
- Threat modeling
- Chaos engineering (Correct answer)
- Vulnerability scanning
- Red team assessment
Correct answer: Chaos engineering
Chaos engineering deliberately injects failures into cloud systems to identify weaknesses in resilience and recovery capabilities before real incidents occur.
Question 4: When evaluating a new cloud vendor's compliance posture, which document provides the most direct evidence of their control environment without requiring a full audit?
- Marketing brochure
- Security whitepaper
- SOC 2 Type II report (Correct answer)
- Service Level Agreement
Correct answer: SOC 2 Type II report
A SOC 2 Type II report is an independent auditor's assessment of a vendor's security controls over time, providing credible third-party evidence.
Question 5: In cloud risk management, what does the term 'concentration risk' refer to?
- The risk of too many security tools creating alert fatigue
- Over-reliance on a single cloud provider for critical business functions (Correct answer)
- High concentration of sensitive data in unencrypted storage
- Risk from concentrating too many privileges in one IAM role
Correct answer: Over-reliance on a single cloud provider for critical business functions
Concentration risk arises when an organization becomes overly dependent on a single cloud provider, creating systemic vulnerability if that provider experiences an outage or failure.
Question 6: Which metric measures the maximum acceptable amount of data loss, expressed as a time period, following a cloud service disruption?
- Recovery Time Objective (RTO)
- Mean Time to Recovery (MTTR)
- Recovery Point Objective (RPO) (Correct answer)
- Maximum Tolerable Downtime (MTD)
Correct answer: Recovery Point Objective (RPO)
Recovery Point Objective (RPO) defines the maximum acceptable age of data that can be recovered after a disruption, expressed as a time period.
Question 7: A CCSE is reviewing a multi-tenant cloud environment where one tenant's misconfigured storage bucket exposes another tenant's data. This scenario is an example of which cloud-specific risk?
- Insider threat
- Supply chain compromise
- Tenant isolation failure (Correct answer)
- Denial of service attack
Correct answer: Tenant isolation failure
Tenant isolation failure occurs when security boundaries between cloud tenants break down, allowing one tenant's actions or data to affect another.
What is the primary goal of a Business Impact Analysis (BIA) in cloud risk management?