CompTIA Cloud Essentials+ (CLO-002)Governance, Risk, Compliance and SecurityHard
A retail chain migrated its inventory system to a cloud provider that uses heavily customized, proprietary APIs and a unique data format not supported by any other vendor. Two years later, the company finds it cannot feasibly switch providers without a costly rebuild. To prevent this in future projects, the IT director mandates that all new cloud deployments use containerized applications built on open-source orchestration platforms. What risk is this policy primarily intended to mitigate?
- ARegulatory non-compliance
- BVendor lock-in
- CInsider threat
- DData breach risk
Show answer & explanationAnswer & explanation
Correct answer: B. Vendor lock-in
Vendor lock-in occurs when proprietary technologies make it difficult or costly to switch providers; using containerization and open standards improves portability and reduces dependency on any single vendor's proprietary architecture.
Why the other options are wrong
- A. Regulatory non-compliance concerns failing legal requirements, not technical portability.
- C. Insider threat concerns malicious or negligent actions by internal personnel, unrelated to this scenario.
- D. Data breach risk relates to unauthorized data access, not portability between providers.
Vendor Lock-In
A situation where a customer becomes dependent on a single cloud provider's proprietary technologies, making it difficult or costly to migrate to another provider.
- Caused by proprietary APIs, data formats, or services
- Mitigated by open standards, containers, and multi-cloud strategies
- Increases switching costs and reduces negotiating leverage
Memory trick: Containers = 'portable boxes' that fit on any truck (cloud)