Practice CLO-002 Governance Risk Compliance And Security questions with full explanations on every answer.
Start practicing
Governance Risk Compliance And Security — choose a session length
Free · No account required
Click any question to see the full explanation and answer options, or start a focused practice session above.
An enterprise is deploying a hybrid cloud model and must ensure that data moving between the on-premises data center and the cloud provider is encrypted. Which mechanism is most appropriate?
2A security analyst notices unauthorized changes to cloud infrastructure. Which service should be analyzed to identify which IAM user made the changes?
3To ensure that all virtual machines in a cloud environment comply with corporate security standards (e.g., specific OS versions), which tool should be used to enforce configuration policies automatically?
4A project manager is reviewing cloud resource usage to ensure compliance with a budget governance policy. Which cloud service dashboard provides the most direct view of current resource costs and budget alerts?
5A company is migrating sensitive financial data to AWS and needs to ensure that all data is encrypted at rest using customer-managed keys. Which service should the administrator configure to manage these keys while maintaining audit logs for compliance?
6An organization is subject to GDPR and needs to ensure that personal data stored in an Azure SQL Database is protected against unauthorized access. Which feature should be enabled to identify potential vulnerabilities and anomalies?
7A cloud architect is defining a security group for a web server. To adhere to the principle of least privilege, which inbound rule should be configured to allow only standard HTTPS traffic?
8An auditor requests evidence that an organization is managing cloud risks. Which document should the IT team provide as the primary evidence of risk mitigation strategies?
9To meet compliance requirements, a firm must store log files for seven years in a read-only state. Which storage configuration provides this level of immutability?
10A company needs to ensure that only authorized devices can access internal cloud applications. Which mechanism verifies device posture before granting access?
11A cloud architect needs to ensure that all cloud resources are tagged with an 'Owner' and 'Environment' tag for governance. Which service helps automate the detection and remediation of non-compliant resources?
12Which cloud computing concept best describes the ability to add and remove resources based on traffic demands to maintain performance?
13After a security incident, it is discovered that a S3 bucket was publicly accessible. Which feature should be used to prevent this from happening in the future?
14To comply with data sovereignty laws, a database must remain within a specific country's borders. Which architectural strategy ensures this?
15A developer is writing code that accesses an API key. Instead of hardcoding the key, which service should they use to retrieve it securely at runtime?
16When following the Shared Responsibility Model, which security aspect is the customer's responsibility in an IaaS environment?
17To ensure that all data is encrypted before being sent to the cloud, which encryption method should the organization employ?
18A company is conducting a risk assessment and needs to determine the impact of a potential cloud service provider outage. Which document provides the provider's commitment to uptime?
19An administrator needs to implement a centralized logging solution for multiple cloud accounts. Which service allows for aggregating security logs into a single security account?
20An organization wants to implement an Identity Provider (IdP) to allow employees to use their corporate credentials for cloud logins. Which protocol is typically used for this purpose?
21A security engineer is setting up a Web Application Firewall (WAF) to protect a public-facing application. Which feature is most effective against common SQL injection attacks?
22Which IAM entity should be created to delegate temporary access to a third-party service provider without sharing long-term credentials?
23To ensure that no single administrator has full control over the environment, which security practice should be implemented?
24A company is evaluating the risk of moving to the cloud. Which business driver is most relevant to 'Agility' in a cloud adoption context?
25A company is using a SaaS application for email. Which part of the security responsibility remains with the company?
26An administrator needs to ensure that only authorized traffic enters a private subnet. Which network component should be configured as a first line of defense?
27A compliance officer needs to generate a report showing all instances that are not compliant with a standard CIS benchmark. Which service should be used?
28What is the primary risk mitigation strategy when storing data in a single availability zone?
29A firm must perform a third-party security audit. What type of document should they obtain from the cloud provider to prove compliance with ISO 27001?
30Which THREE of the following are common benefits of adopting a Cloud Governance framework?
31When a data breach occurs in a cloud environment, who is responsible for notifying the regulatory authorities?
32Which TWO of the following are essential components of a Cloud Security Policy?
33Which TWO of the following are key responsibilities of a Cloud Governance Committee?
34Which THREE of the following represent common compliance risks in a cloud environment?
35Which THREE of the following tools or methods are used to secure data in transit in the cloud?
36Which TWO of the following scenarios represent a breach of the Shared Responsibility Model?
37Which THREE of the following are effective methods for mitigating risks associated with cloud adoption?
38Which TWO of the following are key steps in a Cloud Incident Response process?
39Which THREE of the following are valid reasons for establishing a Cloud Center of Excellence (CCoE)?
40Which TWO of the following are common threats to cloud-based data integrity?
41Which THREE of the following are cloud security best practices?
42Which TWO of the following are benefits of using Infrastructure as Code (IaC) for compliance?
43Which THREE of the following are characteristics of a 'Defense in Depth' security strategy?
The Governance Risk Compliance And Security domain covers the key concepts tested in this area of the CLO-002 exam blueprint published by CompTIA. Courseiva provides free domain-focused practice, mock exams, missed-question review, and readiness tracking across all CLO-002 domains — no account required.
The Courseiva CLO-002 question bank contains 43 questions in the Governance Risk Compliance And Security domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Governance Risk Compliance And Security domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included