CompTIA Cloud Essentials+ (CLO-002)Governance, Risk, Compliance and SecurityHard

A retail company was previously locked into a single cloud provider due to heavy use of proprietary services, causing costly delays when it later needed to migrate. To avoid repeating this problem with a new deployment, the company designs its new application using containerized microservices, open APIs, and infrastructure-as-code templates that can run on multiple cloud platforms. Which strategy is the company pursuing?

  1. ABusiness associate agreement
  2. BData residency compliance
  3. CMulti-cloud portability strategy
  4. DRisk transfer through insurance
Show answer & explanation

Correct answer: C. Multi-cloud portability strategy

A multi-cloud portability strategy uses open standards, containers, and platform-agnostic tooling to design applications that can be deployed or migrated across multiple cloud providers, reducing dependency on any single vendor's proprietary technologies and mitigating vendor lock-in risk.

Why the other options are wrong

  • A. A business associate agreement is a HIPAA-specific contract for handling protected health information, unrelated to this scenario.
  • B. Data residency compliance concerns where data is physically stored to meet legal requirements, unrelated to platform portability.
  • D. Risk transfer through insurance shifts financial impact of a loss to a third party, not a technical design strategy.

Multi-cloud / Portability Strategy

An architectural approach using open standards, containers, and platform-agnostic tools to design applications that can run across multiple cloud providers, reducing vendor lock-in risk.

  • Uses containers, open APIs, and infrastructure-as-code
  • Avoids proprietary provider-specific services where possible
  • Directly mitigates vendor lock-in risk
  • May increase complexity but improves negotiating leverage and flexibility

Memory trick: 'Containers unlock the cage' — portable design frees you from one provider.

More Governance, Risk, Compliance and Security questions