Correct Answer: Cloud discovery to identify sanctioned and shadow application usage, inline enforcement for real-time policy control, API-based scanning for data-at-rest violations in sanctioned apps, and threat protection against compromised cloud accounts
Explanation: Combining discovery, inline enforcement, API-based scanning, and threat protection together provides comprehensive cloud governance, unlike discovery alone with no other controls, inline enforcement alone with no discovery, API scanning alone with no real-time enforcement, limiting policy to one application, or disabling threat protection to reduce alert volume.
Correct Answer: Cloud discovery to identify sanctioned and shadow application usage, inline enforcement for real-time policy control, API-based scanning for data-at-rest violations in sanctioned apps, and threat protection against compromised cloud accounts
Explanation: Combining discovery, inline enforcement, API-based scanning, and threat protection together provides comprehensive cloud governance, unlike discovery alone with no other controls, inline enforcement alone with no discovery, API scanning alone with no real-time enforcement, limiting policy to one application, or disabling threat protection to reduce alert volume.