Certified Cloud Security Professional (CCSP)Legal, Risk and ComplianceHard
A company is migrating its entire on-premises infrastructure to a multi-cloud environment. The security team is conducting a comprehensive risk assessment. They identify that the process of transferring sensitive data between the on-premises data center and the cloud providers, and then between different cloud providers, introduces new attack surfaces. Which of the following risk management strategies is MOST effective in mitigating the risk associated with data transit across these diverse environments?
- AImplementing a robust Data Loss Prevention (DLP) solution at the on-premises perimeter.
- BUtilizing only dedicated network links (e.g., Direct Connect, ExpressRoute) for all data transfers.
- CShifting all data processing to a single, highly secure cloud region.
- DMandating end-to-end encryption for all data in transit, combined with strict key management across all environments.
Show answer & explanationAnswer & explanation
Correct answer: D. Mandating end-to-end encryption for all data in transit, combined with strict key management across all environments.
End-to-end encryption ensures that data remains protected throughout its journey across various environments, regardless of the underlying network or specific cloud provider. Combined with strict key management, it directly mitigates the risk of interception or compromise during transit across diverse and potentially untrusted networks.
Why the other options are wrong
- A. DLP helps prevent unauthorized egress from an internal network but doesn't protect data once it's legitimately in transit between different cloud environments or to/from on-prem.
- B. Dedicated links reduce exposure but don't inherently encrypt the data or protect against internal compromises within the CSP's network or between CSPs without additional controls.
- C. While consolidating processing can simplify some aspects, it doesn't eliminate the need to transfer data to that region, nor does it inherently protect data during transit itself.
End-to-End Encryption in Multi-Cloud Transit
The practice of encrypting data at its source and decrypting it only at its final destination, ensuring protection across multiple network segments and diverse cloud environments.
- Protects data regardless of intervening networks or services.
- Requires robust key management across all involved parties.
- Critical for sensitive data moving between hybrid and multi-cloud.
Memory trick: Data in transit, diverse paths; end-to-end encrypt, or risk the wrath.