Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

CSA CCSK Exam - Topic 2 Question 101 Discussion

Which strategic approach is most appropriate for managing a multi-cloud environment that includes multiple IaaS and PaaS providers?
D) Implement strict governance and monitoring procedures across all platforms.
A) Allow each department to manage their own cloud services independently.
B) Use a single security tool for all providers.
C) Rely on each provider's native security features with limited additional oversight.

CSA CCSK Exam - Topic 2 Question 101 Discussion

Actual exam question for CSA's CCSK exam
Question #: 101
Topic #: 2
[All CCSK Questions]

Which strategic approach is most appropriate for managing a multi-cloud environment that includes multiple IaaS and PaaS providers?

Show Suggested Answer Hide Answer
Suggested Answer: D

In amulti-cloud environment, organizations must implementcentralized governance, security policies, and monitoringto:

Ensure complianceacross multiple providers (AWS, Azure, Google Cloud, etc.).

Standardize security policiesto avoid inconsistencies and misconfigurations.

Use Cloud Security Posture Management (CSPM) toolsto automate security compliance and misconfiguration detection.

Prevent cloud sprawlby enforcing identity and access policies across multiple providers.

This aligns with:

CCSK v5 - Security Guidance v4.0, Domain 2 (Governance and Risk Management)

CSA's Cloud Security Alliance (CCM) - Cloud Security Operations Best Practices.


Contribute your Thoughts:

0/2000 characters
Marylyn
5 hours ago
I think B could lead to gaps in security coverage.
upvoted 0 times
...
Junita
5 days ago
A sounds risky, departments might not coordinate well.
upvoted 0 times
...
Alona
11 days ago
D is definitely the way to go for consistency.
upvoted 0 times
...
Isidra
16 days ago
Using a single security tool sounds convenient, but I wonder if it would really cover all bases. I guess B could be limiting in a multi-cloud scenario.
upvoted 0 times
...
Colette
2 months ago
I think we practiced a question similar to this, and I recall that relying solely on native features could be risky. So, C seems off to me.
upvoted 0 times
...
Joanna
2 months ago
I'm not entirely sure, but I feel like allowing departments to manage their own services could lead to security gaps. Maybe A isn't the way to go?
upvoted 0 times
...
Meaghan
2 months ago
I remember discussing the importance of governance in multi-cloud setups, so I think D might be the best choice.
upvoted 0 times
...

Save Cancel