Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Cloud SecurityMedium
A cloud security team is concerned about the potential for unmanaged and unsanctioned cloud services being used by employees without IT oversight. This practice can introduce significant security risks and compliance gaps. What is this phenomenon commonly referred to, and what is a primary concern for the security team?
- ACloud Sprawl, leading to excessive resource consumption.
- BData Residency, leading to legal and regulatory complications.
- CVendor Lock-in, leading to difficulty in switching cloud providers.
- DShadow IT, leading to unmanaged security risks and compliance issues.
Show answer & explanationAnswer & explanation
Correct answer: D. Shadow IT, leading to unmanaged security risks and compliance issues.
The use of unmanaged and unsanctioned cloud services by employees is known as Shadow IT. The primary concern for the security team is the introduction of unmanaged security risks and potential compliance violations because these services are not under IT's control.
Why the other options are wrong
- A. Cloud sprawl refers to the uncontrolled proliferation of cloud instances and services, often sanctioned but poorly managed, leading to cost issues, not directly unsanctioned services.
- B. Data residency relates to the physical location of data, which can be a concern, but not the direct result of unmanaged and unsanctioned cloud services by employees.
- C. Vendor lock-in is the dependence on a single cloud provider, not related to unsanctioned services.
Shadow IT
The use of IT systems, devices, software, applications, and services without explicit organizational approval or oversight from the IT department.
- Introduces unmanaged security risks
- Can lead to compliance violations
- Often driven by ease of access and user convenience
Memory trick: Shadow IT: Unseen services, unseen dangers.