CompTIA Cloud Essentials+ (CLO-002)Governance, Risk, Compliance and SecurityHard

A company negotiating a new cloud services contract insists on including a clause requiring the provider to export all of the company's data, upon contract termination, in a standard non-proprietary format within 90 days and to assist with migration to a new provider. Which concern is this clause primarily intended to address?

  1. AData sovereignty
  2. BHIPAA compliance
  3. CEncryption key management
  4. DVendor lock-in
Show answer & explanation

Correct answer: D. Vendor lock-in

Including an exit strategy and data portability clause requiring export in a standard, non-proprietary format is a direct mitigation for vendor lock-in, ensuring the organization can migrate to another provider without being trapped by proprietary formats or unreasonable delays. Encryption key management, HIPAA compliance, and data sovereignty are unrelated to the ability to leave a provider and transfer data elsewhere.

Why the other options are wrong

  • A. Data sovereignty concerns which country's laws apply to data, unrelated to switching providers.
  • B. HIPAA compliance concerns healthcare data protections, not contract termination portability.
  • C. Key management concerns who controls encryption keys, not the ability to switch providers.

Exit Strategy / Data Portability Clause

A contractual provision requiring a cloud provider to export customer data in a standard format and assist with migration upon contract termination, mitigating vendor lock-in.

  • Should specify format, timeline, and assistance obligations
  • Reduces dependency on proprietary provider technologies
  • Best negotiated before signing the initial contract, not after

Memory trick: Pack an exit bag (portability clause) before moving into any cloud house so you can leave anytime.

More Governance, Risk, Compliance and Security questions