CompTIA Cloud Essentials+ (CLO-002)Business Principles of Cloud EnvironmentsHard
A large enterprise is performing a cloud gap analysis. They have identified that their existing on-premises security policies, which rely heavily on network segmentation and physical access controls, are not directly transferable to a distributed public cloud environment. This discrepancy primarily represents which type of gap?
- ARegulatory Gap
- BProcess Gap
- CTechnical Gap
- DOrganizational Gap
Show answer & explanationAnswer & explanation
Correct answer: C. Technical Gap
This scenario describes a Technical Gap. The existing security policies, which are technical controls (network segmentation, physical access), are not compatible or effective in the new technical environment (distributed public cloud). It's about the technical mechanisms and architectures that need to change to secure the cloud environment effectively.
Why the other options are wrong
- A. A Regulatory Gap concerns compliance with laws and standards, not the direct technical implementation of policies.
- B. A Process Gap relates to workflows or procedures that need adaptation.
- D. An Organizational Gap relates to skills, roles, or culture within the company.
Technical Gap (Cloud Assessment)
A discrepancy identified during a cloud assessment where existing technical infrastructure, tools, or policies are incompatible or insufficient for the target cloud environment, requiring new technical solutions or adaptations.
- Relates to infrastructure, software, security tools
- Identifies incompatibilities or insufficiencies
- Requires new technical solutions or architectural changes
- Distinct from process, regulatory, or organizational gaps
Memory trick: GAPS: Goals, Architecture, People, Security.