CompTIA Cloud Essentials+ (CLO-002)Governance, Risk, Compliance and SecurityMedium

A software development company uses a public cloud provider for its development and testing environments. Developers frequently provision and de-provision virtual machines and other resources. To ensure cost control and security, the company wants to automatically enforce that all resources are tagged with project, owner, and cost center information, and that non-compliant resources are automatically terminated. Which cloud governance mechanism is best suited for this requirement?

  1. ASecurity Information and Event Management (SIEM)
  2. BData Loss Prevention (DLP)
  3. CCloud Access Security Broker (CASB)
  4. DCloud Policy Engine
Show answer & explanation

Correct answer: D. Cloud Policy Engine

A Cloud Policy Engine allows organizations to define, enforce, and automate governance rules across their cloud environments. It can check for compliance with tagging standards and automatically remediate non-compliant resources, such as terminating untagged virtual machines, directly addressing the scenario's requirements for cost control and security through automated enforcement.

Why the other options are wrong

  • A. SIEM collects and analyzes security events, primarily for detection and alerting, not for automated policy enforcement on resource provisioning.
  • B. DLP prevents sensitive data from leaving defined boundaries and is not designed for enforcing resource tagging or termination policies.
  • C. CASB focuses on security between cloud consumers and providers, often for SaaS applications, and doesn't primarily manage resource tagging and termination within IaaS/PaaS environments.

Cloud Policy Engine

A cloud governance mechanism that enables organizations to define and enforce rules (policies) across their cloud resources to ensure compliance, security, and cost optimization.

  • Automates compliance checks and remediation.
  • Can enforce tagging, resource types, and configurations.
  • Helps maintain security posture and cost control in dynamic cloud environments.

Memory trick: Govern the cloud with careful Policies, Security, and Access.

More Governance, Risk, Compliance and Security questions