CompTIA Cloud Essentials+ (CLO-002)Governance, Risk, Compliance and SecurityHard

A retail chain migrated its inventory system to a cloud provider that uses heavily customized, proprietary APIs and a unique data format not supported by any other vendor. Two years later, the company finds it cannot feasibly switch providers without a costly rebuild. To prevent this in future projects, the IT director mandates that all new cloud deployments use containerized applications built on open-source orchestration platforms. What risk is this policy primarily intended to mitigate?

  1. ARegulatory non-compliance
  2. BVendor lock-in
  3. CInsider threat
  4. DData breach risk
Show answer & explanation

Correct answer: B. Vendor lock-in

Vendor lock-in occurs when proprietary technologies make it difficult or costly to switch providers; using containerization and open standards improves portability and reduces dependency on any single vendor's proprietary architecture.

Why the other options are wrong

  • A. Regulatory non-compliance concerns failing legal requirements, not technical portability.
  • C. Insider threat concerns malicious or negligent actions by internal personnel, unrelated to this scenario.
  • D. Data breach risk relates to unauthorized data access, not portability between providers.

Vendor Lock-In

A situation where a customer becomes dependent on a single cloud provider's proprietary technologies, making it difficult or costly to migrate to another provider.

  • Caused by proprietary APIs, data formats, or services
  • Mitigated by open standards, containers, and multi-cloud strategies
  • Increases switching costs and reduces negotiating leverage

Memory trick: Containers = 'portable boxes' that fit on any truck (cloud)

More Governance, Risk, Compliance and Security questions