Microsoft Cybersecurity Architect (SC-100)Evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategiesEasy
A multinational financial institution is migrating its core banking applications to a hybrid cloud environment. The cybersecurity architect must ensure that all cloud resources are configured securely and continuously monitored for compliance with internal policies and external regulations (e.g., PCI DSS, GDPR). Which GRC technical strategy provides the MOST effective continuous assessment and enforcement of security configurations across this environment?
- AEstablishing a comprehensive security awareness training program for all employees.
- BDeploying a host-based intrusion detection system (HIDS) on all virtual machines.
- CUtilizing Cloud Security Posture Management (CSPM) tools.
- DImplementing a traditional network vulnerability scanner.
Show answer & explanationAnswer & explanation
Correct answer: C. Utilizing Cloud Security Posture Management (CSPM) tools.
Cloud Security Posture Management (CSPM) tools are specifically designed to continuously monitor and assess the security configuration of cloud resources. They identify misconfigurations and compliance deviations against established benchmarks and regulatory standards, making them ideal for hybrid cloud compliance.
Why the other options are wrong
- A. Security awareness training is vital but does not directly provide technical assessment and enforcement of cloud security configurations and compliance.
- B. HIDS focuses on detecting malicious activity on individual VMs, not on assessing and enforcing the overall security posture and compliance of cloud infrastructure.
- D. Traditional vulnerability scanners are not optimized for continuous cloud configuration assessment and compliance enforcement across dynamic cloud environments.
Cloud Security Posture Management (CSPM)
CSPM tools continuously monitor cloud environments for misconfigurations, compliance violations, and security risks, providing visibility and automated remediation capabilities.
- Identifies cloud misconfigurations.
- Ensures compliance with regulatory standards.
- Provides continuous security assessment.
Memory trick: Cloud posture needs a constant watch, CSPM is the watchful eye.