CompTIA SecurityX (CAS-005)Security ArchitectureMedium
A global enterprise is migrating its legacy on-premises applications to a hybrid cloud environment. The security team needs to ensure consistent security policies, threat protection, and secure access for users to applications regardless of their location or the application's hosting environment. Which architectural approach is best suited to meet these requirements?
- ATraditional VPN with on-premises firewalls
- BDistributed firewall appliance deployment
- CClient-side encryption for all data
- DSecurity Service Edge (SSE)
Show answer & explanationAnswer & explanation
Correct answer: D. Security Service Edge (SSE)
Security Service Edge (SSE) is a cloud-centric security model that converges various security services like SWG, CASB, and ZTNA to provide consistent security to users accessing applications anywhere, whether on-premises or in the cloud.
Why the other options are wrong
- A. Traditional VPNs and on-premises firewalls are not agile enough for hybrid cloud and distributed users, leading to inconsistent policies and backhauling traffic.
- B. Distributed firewall appliances would be complex to manage and scale across a hybrid cloud, defeating the purpose of centralized policy.
- C. Client-side encryption helps data at rest/in transit but doesn't address consistent threat protection or access control policies across a hybrid environment.
Security Service Edge (SSE)
A cloud-delivered security model that converges multiple security capabilities, such as Secure Web Gateway (SWG), Cloud Access Security Broker (CASB), and Zero Trust Network Access (ZTNA), to provide consistent security for users accessing applications.
- Cloud-centric and identity-driven.
- Enables secure access from anywhere, to anything.
- Consolidates security functions for simplified management.
Memory trick: SSE is the 'cloud security umbrella' for your hybrid world.