CLO-002 · domain
Governance Risk Compliance And Security
Practise CompTIA Cloud Essentials+ (CLO-002) (CLO-002) Governance Risk Compliance And Security practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice Governance Risk Compliance And Security questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Governance Risk Compliance And Security
Governance Risk Compliance And Security questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common Governance Risk Compliance And Security exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All Governance Risk Compliance And Security questions (43)
Click any question to see the full explanation, or start a practice session above.
A company is conducting a risk assessment and needs to determine the impact of a potential cloud service provider outage. Which document provides the provider's commitment to uptime?
Medium2A security engineer is setting up a Web Application Firewall (WAF) to protect a public-facing application. Which feature is most effective against common SQL injection attacks?
Hard3Which cloud computing concept best describes the ability to add and remove resources based on traffic demands to maintain performance?
Easy4An auditor requests evidence that an organization is managing cloud risks. Which document should the IT team provide as the primary evidence of risk mitigation strategies?
Easy5To ensure that no single administrator has full control over the environment, which security practice should be implemented?
Medium6To meet compliance requirements, a firm must store log files for seven years in a read-only state. Which storage configuration provides this level of immutability?
Medium7A security analyst notices unauthorized changes to cloud infrastructure. Which service should be analyzed to identify which IAM user made the changes?
Medium8Which THREE of the following are effective methods for mitigating risks associated with cloud adoption?
Medium9After a security incident, it is discovered that a S3 bucket was publicly accessible. Which feature should be used to prevent this from happening in the future?
Hard10Which THREE of the following are cloud security best practices?
Medium11Which THREE of the following are characteristics of a 'Defense in Depth' security strategy?
Hard12An organization is subject to GDPR and needs to ensure that personal data stored in an Azure SQL Database is protected against unauthorized access. Which feature should be enabled to identify potential vulnerabilities and anomalies?
Hard13Which TWO of the following scenarios represent a breach of the Shared Responsibility Model?
Hard14An enterprise is deploying a hybrid cloud model and must ensure that data moving between the on-premises data center and the cloud provider is encrypted. Which mechanism is most appropriate?
Hard15A firm must perform a third-party security audit. What type of document should they obtain from the cloud provider to prove compliance with ISO 27001?
Hard16Which TWO of the following are essential components of a Cloud Security Policy?
Medium17When following the Shared Responsibility Model, which security aspect is the customer's responsibility in an IaaS environment?
Easy18To comply with data sovereignty laws, a database must remain within a specific country's borders. Which architectural strategy ensures this?
Hard19An administrator needs to ensure that only authorized traffic enters a private subnet. Which network component should be configured as a first line of defense?
Medium20An administrator needs to implement a centralized logging solution for multiple cloud accounts. Which service allows for aggregating security logs into a single security account?
Hard21Which THREE of the following are valid reasons for establishing a Cloud Center of Excellence (CCoE)?
Medium22A cloud architect needs to ensure that all cloud resources are tagged with an 'Owner' and 'Environment' tag for governance. Which service helps automate the detection and remediation of non-compliant resources?
Medium23When a data breach occurs in a cloud environment, who is responsible for notifying the regulatory authorities?
Easy24Which THREE of the following are common benefits of adopting a Cloud Governance framework?
Medium25A project manager is reviewing cloud resource usage to ensure compliance with a budget governance policy. Which cloud service dashboard provides the most direct view of current resource costs and budget alerts?
Easy26Which THREE of the following tools or methods are used to secure data in transit in the cloud?
Medium27Which TWO of the following are key responsibilities of a Cloud Governance Committee?
Medium28A compliance officer needs to generate a report showing all instances that are not compliant with a standard CIS benchmark. Which service should be used?
Hard29A company needs to ensure that only authorized devices can access internal cloud applications. Which mechanism verifies device posture before granting access?
Medium30To ensure that all virtual machines in a cloud environment comply with corporate security standards (e.g., specific OS versions), which tool should be used to enforce configuration policies automatically?
Medium31An organization wants to implement an Identity Provider (IdP) to allow employees to use their corporate credentials for cloud logins. Which protocol is typically used for this purpose?
Easy32A company is evaluating the risk of moving to the cloud. Which business driver is most relevant to 'Agility' in a cloud adoption context?
Easy33Which TWO of the following are benefits of using Infrastructure as Code (IaC) for compliance?
Medium34A company is migrating sensitive financial data to AWS and needs to ensure that all data is encrypted at rest using customer-managed keys. Which service should the administrator configure to manage these keys while maintaining audit logs for compliance?
Medium35Which TWO of the following are key steps in a Cloud Incident Response process?
Hard36Which TWO of the following are common threats to cloud-based data integrity?
Hard37Which THREE of the following represent common compliance risks in a cloud environment?
Hard38What is the primary risk mitigation strategy when storing data in a single availability zone?
Medium39To ensure that all data is encrypted before being sent to the cloud, which encryption method should the organization employ?
Medium40A company is using a SaaS application for email. Which part of the security responsibility remains with the company?
Medium41A developer is writing code that accesses an API key. Instead of hardcoding the key, which service should they use to retrieve it securely at runtime?
Medium42Which IAM entity should be created to delegate temporary access to a third-party service provider without sharing long-term credentials?
Medium43A cloud architect is defining a security group for a web server. To adhere to the principle of least privilege, which inbound rule should be configured to allow only standard HTTPS traffic?
MediumOther domains
All CLO-002 exam domains
Frequently asked questions
- What does the Governance Risk Compliance And Security domain cover on the CLO-002 exam?
- Governance Risk Compliance And Security questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 43 Governance Risk Compliance And Security questions in the CLO-002 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Governance Risk Compliance And Security questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.