Risk Assessment & Management Flashcards
7 cards from real Cloud Engineer practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Risk Assessment & Management flashcards as text
A cloud team is conducting a risk assessment for a new AI/ML workload that processes PII. Which privacy regulation is most directly relevant for a US-based healthcare dataset?
Answer: HIPAA
HIPAA governs Protected Health Information (PHI) in the US, making it the primary compliance framework for healthcare PII on cloud workloads.
An organization runs critical workloads on AWS. Leadership wants to understand what risks remain after all current security controls are applied. This is called:
Answer: Residual risk
Residual risk is the exposure that remains after compensating controls have been implemented—it must stay within the organization's risk appetite.
A cloud engineer discovers that a critical security patch cannot be applied because it breaks a legacy application. The team documents the vulnerability and monitors it closely instead. This approach is an example of:
Answer: Compensating control / risk acceptance with monitoring
When patching isn't feasible, applying compensating controls and increasing monitoring is a structured form of informed risk acceptance.
Which AWS service provides a continuous risk and compliance assessment by checking resource configurations against security best practices?
Answer: AWS Config with Conformance Packs
AWS Config with Conformance Packs evaluates resource configurations against compliance frameworks (CIS, PCI, NIST) on a continuous basis.
During risk prioritization, which scoring model uses five factors—Damage, Reproducibility, Exploitability, Affected users, and Discoverability—to rate vulnerabilities?
Answer: DREAD
DREAD is a Microsoft-originated vulnerability scoring model using five factors to produce a numeric risk score for prioritization.
A risk owner has been assigned to a critical cloud database risk. What is the primary responsibility of a risk owner?
Answer: Ensure that treatment plans are implemented and the risk is monitored over time
The risk owner is accountable for ensuring that the agreed treatment plan is executed and that residual risk stays within acceptable bounds.
Which risk assessment technique involves gathering structured input from multiple subject matter experts through iterative anonymous questionnaires?
Answer: Delphi technique
The Delphi technique uses anonymous expert rounds to reach consensus on risk likelihood and impact, reducing groupthink bias.