Certified Cloud Security Professional (CCSP)Cloud Application SecurityHard

A cloud application development team is migrating a legacy application that relies heavily on a relational database containing highly sensitive customer information. The team needs to ensure that this data is protected from unauthorized access, both from outside the cloud environment and from other applications within the same cloud provider, even if the underlying infrastructure is compromised. Which data isolation strategy offers the STRONGEST protection for this scenario?

  1. AImplementing row-level security within the database.
  2. BUsing a dedicated database instance for the application.
  3. CDeploying the application and database in a separate cloud account/subscription.
  4. DLogical separation using database schemas and user permissions.
Show answer & explanation

Correct answer: C. Deploying the application and database in a separate cloud account/subscription.

Deploying the application and its dedicated database in a separate cloud account/subscription provides the strongest isolation. This creates a hard boundary managed by the cloud provider's IAM system, ensuring that even if one account is compromised, the other remains protected. It isolates not just the data, but also the management plane and access controls.

Why the other options are wrong

  • A. Row-level security offers granular data protection within a database but does not protect against broader infrastructure or account compromises.
  • B. A dedicated database instance offers better isolation than shared instances but still exists within the same cloud account and network boundaries, making it potentially vulnerable to broader account compromises.
  • D. Logical separation via schemas and permissions is good practice but relies on the integrity of the database itself and is susceptible if the database host or administrative access is compromised.

Cloud Account/Subscription Isolation

A multi-tenancy isolation strategy where different applications or environments are deployed into entirely separate cloud accounts or subscriptions, providing the highest level of administrative and security boundary isolation.

  • Strongest form of isolation.
  • Separate IAM, networking, billing boundaries.
  • Protects against cross-account compromise.

Memory trick: Each application gets its own castle, with its own drawbridge and guards, not just a room in a shared palace.

More Cloud Application Security questions