Certified Cloud Security Professional (CCSP)Cloud Concepts, Architecture and DesignMedium

A startup is building a new application that will collect and process user data. To minimize costs and maximize scalability, they plan to use various cloud services from a single public cloud provider. However, the legal team is concerned about vendor lock-in and the potential difficulty of migrating to a different provider in the future. Which cloud security best practice should the startup prioritize to mitigate this risk?

  1. AEncrypting all data at rest and in transit.
  2. BDesigning with cloud-agnostic architectures and open standards.
  3. CImplementing strong identity and access management (IAM) policies.
  4. DConducting regular security audits and penetration testing.
Show answer & explanation

Correct answer: B. Designing with cloud-agnostic architectures and open standards.

Designing with cloud-agnostic architectures and open standards directly addresses vendor lock-in by reducing reliance on proprietary cloud services and making it easier to port applications and data between different cloud environments.

Why the other options are wrong

  • A. Encryption is a fundamental security control but doesn't prevent vendor lock-in.
  • C. IAM is crucial for security but doesn't directly mitigate vendor lock-in.
  • D. Audits and penetration testing enhance security but do not solve the problem of vendor lock-in.

Cloud-Agnostic Architecture

A design philosophy that aims to create cloud applications and services that can run on any cloud provider's infrastructure with minimal or no changes.

  • Reduces vendor lock-in
  • Increases portability and flexibility
  • Often relies on open standards and containerization

Memory trick: Secure clouds are Agnostic, Encrypted, and Audited.

More Cloud Concepts, Architecture and Design questions