nerdexam
Isaca

CCAK · Question #73

Account design in the cloud should be driven by:

The correct answer is A. security requirements. Cloud account architecture (e.g., AWS accounts, Azure subscriptions, GCP projects) establishes the foundational boundaries for access control, network segmentation, blast radius containment, and compliance scope. Security requirements must be the primary driver because account…

Cloud Governance

Question

Account design in the cloud should be driven by:

Options

  • Asecurity requirements.
  • Borganizational structure.
  • Cbusiness continuity policies.
  • Dmanagement structure.

How the community answered

(18 responses)
  • A
    89% (16)
  • C
    6% (1)
  • D
    6% (1)

Explanation

Cloud account architecture (e.g., AWS accounts, Azure subscriptions, GCP projects) establishes the foundational boundaries for access control, network segmentation, blast radius containment, and compliance scope. Security requirements must be the primary driver because account design decisions are extremely difficult to reverse and have cascading security implications. While organizational structure, management hierarchy, and business continuity considerations may influence design, they are secondary to ensuring the architecture enforces least privilege, separation of duties, and proper isolation from a security standpoint.

Topics

#Cloud Account Design#Cloud Security Architecture#Identity and Access Management#Security Controls

Community Discussion

No community discussion yet for this question.

Full CCAK Practice