Certified Cloud Security Professional (CCSP)Cloud Concepts, Architecture and DesignMedium
A security architect is reviewing a proposed cloud deployment for a new application that will store highly sensitive customer data, including personally identifiable information (PII) and protected health information (PHI). The architect is particularly concerned about the risk of data compromise due to a misconfiguration in the cloud environment. Which design principle should be most heavily emphasized to minimize this risk?
- AResource Pooling
- BShared Responsibility Model
- CSecure Defaults
- DBroad Network Access
Show answer & explanationAnswer & explanation
Correct answer: C. Secure Defaults
Secure defaults ensure that systems and services are configured with the most secure settings out-of-the-box, significantly reducing the attack surface and the likelihood of misconfigurations that could lead to data compromise, especially with highly sensitive data.
Why the other options are wrong
- A. Resource Pooling is a characteristic of cloud, not a security design principle to prevent misconfiguration.
- B. The Shared Responsibility Model defines who is responsible for what, but 'Secure Defaults' is a principle applied within that model to prevent misconfigurations.
- D. Broad Network Access is a characteristic of cloud computing, not a design principle for security against misconfiguration.
Secure Defaults
A security design principle advocating that systems and services should be configured with the most secure settings by default, requiring explicit action to reduce security.
- Minimizes misconfiguration risks
- Reduces attack surface out-of-the-box
- Enhances overall system security posture
Memory trick: Secure defaults set you up for success.