Risk Assessment & Management Flashcards
7 cards from real Cloud Engineer practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Risk Assessment & Management flashcards as text
Which formula correctly calculates Annualized Loss Expectancy (ALE)?
Answer: ALE = SLE × ARO
ALE = SLE (Single Loss Expectancy) × ARO (Annualized Rate of Occurrence), giving the expected annual financial loss from a specific risk.
A cloud governance team wants to ensure that residual risk after applying controls stays below the organization's risk appetite. What term describes this acceptable level of remaining risk?
Answer: Risk appetite
Risk appetite is the total amount of risk an organization is willing to accept in pursuit of its objectives, setting the boundary for residual risk.
During a cloud security review, a risk is identified as having low likelihood but catastrophic impact. How should this risk be prioritized on a risk matrix?
Answer: Moderate to high priority — impact drives significance for low-frequency/high-consequence events
Risks with catastrophic impact demand elevated prioritization even at low likelihood because the consequences of a single occurrence can be devastating.
Which NIST document provides a risk management framework widely used for cloud environments in U.S. federal agencies?
Answer: NIST SP 800-37 (RMF)
NIST SP 800-37 defines the Risk Management Framework (RMF), a six-step process for selecting, implementing, and monitoring security controls.
A cloud engineer is assessing risk for a multi-tenant Kubernetes cluster. Which threat modeling approach focuses on attacker goals rather than system assets?
Answer: PASTA
PASTA (Process for Attack Simulation and Threat Analysis) is attacker-centric, simulating adversary goals and correlating them with business impact.
What is the purpose of a Business Impact Analysis (BIA) in cloud risk management?
Answer: Determine the criticality of systems and the financial/operational effect of their disruption
A BIA quantifies the operational and financial consequences of losing specific cloud services, driving RTO and RPO targets.
Which control type is designed to detect risk events after they have occurred rather than prevent them?
Answer: Detective control
Detective controls—such as CloudTrail logs and SIEM alerts—identify when a risk event has occurred so it can be investigated and remediated.