CompTIA Cloud Essentials+ (CLO-002)Management and Technical OperationsMedium
A cloud security engineer is implementing a policy to ensure that all sensitive data stored in object storage buckets is encrypted at rest and in transit. Which of the following is the MOST effective approach to enforce this across all new and existing buckets?
- ADevelop a custom script to periodically check and update bucket encryption settings.
- BManually configure encryption settings for each bucket via the cloud console.
- CImplement a cloud governance policy engine to automatically enforce encryption settings.
- DUtilize a Cloud Access Security Broker (CASB) to intercept and encrypt data during upload.
Show answer & explanationAnswer & explanation
Correct answer: C. Implement a cloud governance policy engine to automatically enforce encryption settings.
A cloud governance policy engine provides a centralized, automated, and continuous method to ensure compliance with security policies across all cloud resources, including enforcing encryption for new and existing storage buckets.
Why the other options are wrong
- A. A custom script can help, but it's reactive and requires maintenance, lacking the proactive enforcement of a policy engine.
- B. Manual configuration is error-prone and not scalable for enforcing policies across many resources.
- D. A CASB can add an encryption layer but might not directly enforce the native bucket encryption settings or be the primary enforcement mechanism for cloud-native resources.
Cloud Governance Policy Engine
A system that defines, evaluates, and enforces compliance rules and security policies across cloud resources, often automatically remedying non-compliant configurations.
- Provides automated policy enforcement.
- Ensures continuous compliance and security.
- Reduces manual overhead and human error.
Memory trick: Policies Guard All Cloud Boundaries.