AND ANSWERS
Which of the following statements are NOT requirements of governance and enterprise
risk management in a cloud environment?
A. Inspect and account for risks inherited from other members of the cloud supply chain
and take active measures to mitigate and contain risks through operational resiliency.
B. Respect the interdependency of the risks inherent in the cloud supply chain and
communicate the corporate risk posture and readiness to consumers and dependent
parties.
C. Negotiate long-term contracts with companies who use well-vetted software
application to avoid the transient nature of the cloud environment.
D. Provide transparency to stakeholders and shareholders demonstrating fiscal
solvency and organizational transparency.
E. Both B and C. - Answer- C
What is defined as the process by which an opposing party may obtain private
documents for use in litigation?
A. Discovery
B. Custody
C. Subpoena
D. Risk Assessment
E. Scope - Answer- A
What item below allows disparate directory services and independent security domains
to be interconnected?
A. Coalition
B. Cloud
C. Intersection
D. Union
E. Federation - Answer- E
Use elastic servers when possible and move workloads to new instances.
A. False
B. True - Answer- B
, To understand their compliance alignments and gaps with a cloud provider, what must
cloud customers rely on?
A. Provider documentation
B. Provider run audits and reports
C. Third-party attestations
D. Provider and consumer contracts
E. EDiscovery tools - Answer- C
Which of the following is a perceived advantage or disadvantage of managing
enterprise risk for cloud deployments?
A. More physical control over assets and processes.
B. Greater reliance on contracts, audits, and assessments due to lack of visibility or
management.
C. Decreased requirement for proactive management of relationship and adherence to
contracts.
D. Increased need, but reduction in costs, for managing risks accepted by the cloud
provider.
E. None of the above. - Answer- B
Which data security control is the LEAST likely to be assigned to an IaaS provider?
A. Application logic
B. Access controls
C. Encryption solutions
D. Physical destruction
E. Asset management and tracking - Answer- A
How does virtualized storage help avoid data loss if a drive fails?
A. Multiple copies in different locations
B. Drives are backed up, swapped, and archived constantly
C. Full back ups weekly
D. Data loss is unavoidable with drive failures
E. Incremental backups daily - Answer- A
A cloud deployment of two or more unique clouds is known as:
A. Infrastructures as a Service
B. A Private Cloud
C. A Community Cloud
D. A Hybrid Cloud
E. Jericho Cloud Cube Model - Answer- C
ENISA: Which is not one of the five key legal issues common across all scenarios: