ISC2 Certified Cloud Security Professional (CCSP) Practice Question

A retail company plans to host its public web portal in a single IaaS region and is performing a quantitative risk assessment. The portal itself is valued at USD 500,000, and the security team estimates that a successful volumetric DDoS attack would render 40 percent of that value unrecoverable because of lost sales and recovery costs. Industry data for similar tenants show two successful DDoS incidents every five years. What is the annualized loss expectancy (ALE) for this risk and the most appropriate interpretation when deciding whether to fund cloud-based DDoS mitigation?

  • Approximately USD 500,000; the risk is catastrophic and requires immediate multi-region redundancy.

  • Approximately USD 200,000; the risk should be transferred entirely through cyber-insurance.

  • Approximately USD 80,000; the risk is significant enough to justify investing in DDoS mitigation controls.

  • Approximately USD 40,000; the risk is low enough to accept without new controls.

ISC2 Certified Cloud Security Professional (CCSP)
Cloud Platform & Infrastructure Security
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot