CCSP - Cloud Platform and Infrastructure Security - Section 3.3

Analyze risks associated with cloud infrastructure and platforms.

Risk assessment methodologies, cloud vulnerabilities, threats and attack vectors, and the risk mitigation strategies proportionate to each.

risk assessment methodologycloud vulnerabilities and threatsattack vectorsrisk treatment optionsresidual risk

Practice question for this objective

Free sampleCloud Platform and Infrastructure Securityhard

After a cloud infrastructure risk assessment, an organisation deploys additional network segmentation and tighter identity controls to reduce an identified threat. Which term describes the risk that remains after these controls are applied?

  • AInherent risk, the level of risk present before any controls are considered
  • BResidual risk, the level of risk that persists after controls have been applied Correct
  • CTotal risk, the sum of every threat facing the environment before treatment
  • DSecondary risk, a new risk introduced by the act of treating another risk
Distinguish residual risk from inherent, total, and secondary risk in a cloud infrastructure risk treatment cycle. Controls reduce inherent risk but rarely eliminate it; the exposure still present once controls are operating is residual risk, which management must formally accept or treat further before it is acceptable.

Why A is wrong: Inherent risk is the exposure that exists before controls are applied, so it describes the starting point rather than what remains after the segmentation and identity controls are in place.

Why B is correct: Residual risk is precisely the exposure that remains once selected controls have been implemented, which is what the organisation must accept, transfer, or treat further.

Why C is wrong: This describes an aggregate pre-treatment view of exposure and does not capture the specific concept of what is left over after controls are applied.

Why D is wrong: Secondary risk is a fresh exposure created by a response action, not the remaining portion of the original risk after controls are applied.

See more CCSP practice questions, answers explained.

More in this domain

Back to all Cloud Platform and Infrastructure Security objectives, or the CCSP cert hub.

Examworthy is not affiliated with or endorsed by ISC2. Original, blueprint-aligned practice material only.