1. A global enterprise is expanding its cloud footprint, utilizing multiple cloud providers (Azure, AWS, GCP) and numerous SaaS applications. The cybersecurity architect needs to implement a security operations strategy that provides unified visibility, threat detection, and automated response capabilities across this complex multi-cloud and SaaS environment. Traditional on-premises SIEM/SOAR solutions are proving inadequate. Which strategy should the architect prioritize?
Evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategies
- A. Deploying a cloud-native Extended Detection and Response (XDR) solution.
- B. Enhancing existing on-premises SIEM with cloud connectors.
- C. Implementing separate, native security services for each cloud provider.
- D. Focusing on security awareness training for all cloud users.
Show answerAnswer
A. Deploying a cloud-native Extended Detection and Response (XDR) solution.
A cloud-native XDR solution is designed to provide unified visibility, threat detection, and automated response across diverse environments, including multi-cloud, SaaS, endpoints, and identities. This consolidates security data and streamlines operations far more effectively than disparate native services or extended on-premises SIEMs.