400-007 · Question #386
End users are moving swiftly toward a hybrid cloud model to support faster IT service delivery. To implement a hybrid cloud architecture, what are two critical requirements for broader cloud service…
The correct answer is A. cloud integration and data security C. security event and data interoperability. Hybrid cloud interoperability for security and compliance fundamentally requires both integrated data security across environments and the ability to share and normalize security events between cloud providers.
Question
End users are moving swiftly toward a hybrid cloud model to support faster IT service delivery. To implement a hybrid cloud architecture, what are two critical requirements for broader cloud service provider and vendor interoperability in terms of cloud security and compliance? (Choose two.)
Options
- Acloud integration and data security
- Btighter controls based on dynamic policy enforcement
- Csecurity event and data interoperability
- Dflexible controls based on policy application
- Eorchestration and cross cloud access security
How the community answered
(25 responses)- A76% (19)
- B8% (2)
- D12% (3)
- E4% (1)
Why each option
Hybrid cloud interoperability for security and compliance fundamentally requires both integrated data security across environments and the ability to share and normalize security events between cloud providers.
Cloud integration and data security is a foundational requirement because hybrid cloud environments must exchange workloads and data across on-premises and multiple cloud platforms while maintaining consistent data protection policies - without integrated security controls spanning all environments, data exposure and compliance gaps inevitably emerge.
Dynamic policy enforcement is a useful control mechanism but it describes an enforcement capability rather than a foundational interoperability requirement between cloud service providers and vendors.
Security event and data interoperability is critical because security teams must correlate logs and alerts from disparate cloud providers to detect threats and satisfy compliance mandates - if security data cannot be shared and normalized across platforms, visibility gaps emerge that attackers can exploit and auditors cannot reconcile.
Flexible controls based on policy application describes a general security posture preference and is not a specific technical interoperability requirement needed for cross-cloud security and compliance.
Orchestration and cross-cloud access security describes operational tooling and access management capabilities rather than the core interoperability requirements that enable cloud providers and vendors to work together securely.
Concept tested: Hybrid cloud security and compliance interoperability requirements
Source: https://cloudsecurityalliance.org/research/guidance/
Topics
Community Discussion
No community discussion yet for this question.