CLO-002 Governance Risk Compliance And Security Practice Question
Which THREE of the following are effective methods for mitigating risks associated with cloud adoption?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Performing periodic penetration tests
Risk mitigation includes regular audits, automated security controls, and strict identity management.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Performing periodic penetration tests
Why this is correct
Testing identifies vulnerabilities before attackers do.
- ✗
Reducing the number of cloud regions used
Why it's wrong here
This limits availability, not risk.
- ✗
Using only one cloud provider
Why it's wrong here
Single-sourcing increases vendor lock-in risk.
- ✓
Implementing automated compliance monitoring
Why this is correct
Automation reduces human error in compliance.
- ✓
Requiring multi-factor authentication for all users
Why this is correct
MFA is a standard control for mitigating credential theft.
About these practice questions
Courseiva writes every CLO-002 question from scratch — 211 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official CompTIA exam blueprint
This CLO-002 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLO-002 exam.