Cisco CCNP Security Core (SCOR) 350-701Cloud SecurityHard

A financial services organization is adopting a multi-cloud strategy. They need a solution to ensure consistent security policies, identity management, and compliance enforcement across different cloud providers (e.g., AWS, Azure, GCP). The solution should provide a unified view of their security posture and automate policy enforcement without requiring separate configurations for each cloud. Which approach would be most effective?

  1. AUtilizing a Cloud Native Application Protection Platform (CNAPP)
  2. BLeveraging each cloud provider's native Identity and Access Management (IAM) service independently
  3. CImplementing a separate CSPM tool for each cloud provider
  4. DDeploying a dedicated WAF in front of each application
Show answer & explanation

Correct answer: A. Utilizing a Cloud Native Application Protection Platform (CNAPP)

A CNAPP provides a unified platform that integrates various cloud security capabilities, including CSPM, CIEM, workload protection, and vulnerability management, across multiple cloud environments. This allows for consistent policy enforcement, identity management, and security posture visibility from a single pane of glass, which is crucial for multi-cloud consistency.

Why the other options are wrong

  • B. Leveraging native IAM independently across clouds would create identity silos and hinder consistent policy enforcement and central management.
  • C. Separate CSPM tools for each cloud would lead to fragmented visibility and inconsistent policy enforcement, directly contradicting the 'consistent security policies' requirement.
  • D. WAFs protect web applications from specific attacks, but do not provide consistent security policies or identity management across a multi-cloud environment.

Cloud Native Application Protection Platform (CNAPP)

A unified security platform that consolidates multiple cloud-native security capabilities (CSPM, CIEM, CWPP, KSPM, etc.) into a single offering to protect cloud applications from development to runtime.

  • Provides end-to-end security for cloud-native applications.
  • Offers unified visibility and policy enforcement across multi-cloud environments.
  • Integrates security across the entire application lifecycle (code, build, deploy, run).

Memory trick: CNAPP is the 'C'entral 'N'erve 'A'nd 'P'rotection 'P'latform for all your cloud apps.

More Cloud Security questions