Certified Cloud Security Professional – CCSP – Question366

Which of the following would be considered an example of insufficient due diligence leading to security or operational problems when moving to a cloud?

A.
Monitoring
B. Use of a remote key management system
C. Programming languages used
D. Reliance on physical network controls

Correct Answer: D

Explanation:

Explanation: Many organizations in a traditional data center make heavy use of physical network controls for security. Although this is a perfectly acceptable best practice in a traditional data center, this reliance is not something that will port to a cloud environment. The failure of an organization to properly understand and adapt to the difference in network controls when moving to a cloud will likely leave an application with security holes and vulnerabilities. The use of a remote key management system, monitoring, or certain programming languages would not constitute insufficient due diligence by itself.