Risk Assessment & Management Flashcards
7 cards from real Cloud Engineer practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Risk Assessment & Management flashcards as text
A cloud architect is designing a risk treatment plan for a DDoS threat against a public-facing API. Selecting AWS Shield Advanced transfers some financial risk because:
Answer: It includes Cost Protection that reimburses scaling costs incurred during a DDoS attack
AWS Shield Advanced Cost Protection reimburses EC2, CloudFront, and Route 53 scaling charges triggered by a DDoS event, financially transferring that risk to AWS.
A secondary risk is best described as:
Answer: A new risk introduced by implementing a risk treatment
Secondary risks emerge as side effects of treatment actions—for example, a new vulnerability created by installing a third-party patch management tool.
Which cloud security framework maps controls to risk categories and provides a Cloud Controls Matrix (CCM) specifically for cloud providers and customers?
Answer: CSA STAR / CCM
The Cloud Security Alliance (CSA) Cloud Controls Matrix is purpose-built for cloud environments, mapping security domains to compliance requirements.
An organization uses a risk heat map to visualize its risk portfolio. A risk plotted in the upper-right quadrant indicates:
Answer: High likelihood and high impact
Heat maps plot likelihood on one axis and impact on the other; the upper-right quadrant represents risks that are both highly likely and severely impactful.
When performing a cloud vendor risk assessment, which artifact best demonstrates that a cloud provider's security controls have been independently verified?
Answer: A SOC 2 Type II audit report
A SOC 2 Type II report is issued by an independent auditor and attests that the vendor's controls were operating effectively over an audit period.
Which technique uses probability distributions and thousands of simulated scenarios to model the range of possible financial outcomes from a cloud risk?
Answer: Monte Carlo simulation
Monte Carlo simulation runs thousands of random iterations across probability distributions to produce a range of likely financial outcomes, supporting quantitative risk decisions.
A cloud governance board reviews a risk that has been accepted for 18 months without re-evaluation. What risk management principle does this violate?
Answer: Continuous risk monitoring and periodic reassessment
Risk management requires periodic reassessment because threat landscapes, asset values, and control effectiveness change over time; stale accepted risks must be reviewed.