CompTIA Cloud Essentials+ (CLO-002)Governance, Risk, Compliance and SecurityHard
A retail company was previously locked into a single cloud provider due to heavy use of proprietary services, causing costly delays when it later needed to migrate. To avoid repeating this problem with a new deployment, the company designs its new application using containerized microservices, open APIs, and infrastructure-as-code templates that can run on multiple cloud platforms. Which strategy is the company pursuing?
- ABusiness associate agreement
- BData residency compliance
- CMulti-cloud portability strategy
- DRisk transfer through insurance
Show answer & explanationAnswer & explanation
Correct answer: C. Multi-cloud portability strategy
A multi-cloud portability strategy uses open standards, containers, and platform-agnostic tooling to design applications that can be deployed or migrated across multiple cloud providers, reducing dependency on any single vendor's proprietary technologies and mitigating vendor lock-in risk.
Why the other options are wrong
- A. A business associate agreement is a HIPAA-specific contract for handling protected health information, unrelated to this scenario.
- B. Data residency compliance concerns where data is physically stored to meet legal requirements, unrelated to platform portability.
- D. Risk transfer through insurance shifts financial impact of a loss to a third party, not a technical design strategy.
Multi-cloud / Portability Strategy
An architectural approach using open standards, containers, and platform-agnostic tools to design applications that can run across multiple cloud providers, reducing vendor lock-in risk.
- Uses containers, open APIs, and infrastructure-as-code
- Avoids proprietary provider-specific services where possible
- Directly mitigates vendor lock-in risk
- May increase complexity but improves negotiating leverage and flexibility
Memory trick: 'Containers unlock the cage' — portable design frees you from one provider.