Risk Assessment & Management Flashcards
7 cards from real Cloud Engineer practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Risk Assessment & Management flashcards as text
A cloud engineer must quantify the potential financial impact of a data breach affecting 50,000 customer records. Which metric best expresses this as a single dollar figure?
Answer: Single Loss Expectancy (SLE)
Single Loss Expectancy (SLE) = Asset Value × Exposure Factor and represents the financial loss from one occurrence of a specific risk event.
Which risk treatment option is most appropriate when the cost of mitigating a vulnerability exceeds the value of the asset it protects?
Answer: Risk acceptance
Risk acceptance is used when the cost of controls exceeds the potential loss, making it economically rational to tolerate the risk.
A company stores sensitive data in AWS S3. A penetration test reveals a misconfigured bucket policy that exposes data publicly. In the risk register, this misconfiguration is classified as:
Answer: A vulnerability
A vulnerability is a weakness in a system—here the misconfigured bucket policy—that can be exploited by a threat actor.
During a cloud risk assessment, you discover that a third-party SaaS provider has access to your production database. Which risk category does this primarily represent?
Answer: Supply chain / third-party risk
Third-party vendor access introduces supply chain risk because the organization's security posture depends on the vendor's controls.
Which document formally records identified risks, their likelihood, impact ratings, owners, and treatment plans for a cloud environment?
Answer: Risk register
A risk register is the authoritative log that tracks all identified risks along with their assessments, owners, and mitigation status.
An organization wants to transfer cloud infrastructure risk associated with hardware failure. Which mechanism most directly achieves this?
Answer: Purchasing cyber liability insurance
Cyber liability insurance transfers financial risk to an insurer, shifting the monetary burden of incidents away from the organization.
A qualitative risk assessment rates risks using categories like High, Medium, and Low. What is the primary advantage of qualitative over quantitative assessment?
Answer: It is faster and requires less data to perform
Qualitative assessments use subjective scales and expert judgment, making them quicker to execute when precise financial data is unavailable.