Which combination of practices would provide strong, consistent security posture and compliance across an organization using AWS, Azure, and GCP together?
Correct Answer: Applying the Shared Responsibility Model correctly for each provider, using each provider's native governance constructs (IAM policies, Azure Policy, Organization Policy Service), and continuously monitoring posture with a cross-cloud CSPM tool
Explanation: Correctly applying shared responsibility, using each provider's native governance tools, and continuous cross-cloud CSPM monitoring together provide strong, consistent posture, unlike a set-once configuration with no ongoing monitoring, ignoring native governance constructs, assuming identical responsibility boundaries across providers, disabling monitoring for smaller deployments regardless of sensitivity, or relying solely on manual ad hoc review.
Correct Answer: Applying the Shared Responsibility Model correctly for each provider, using each provider's native governance constructs (IAM policies, Azure Policy, Organization Policy Service), and continuously monitoring posture with a cross-cloud CSPM tool
Explanation: Correctly applying shared responsibility, using each provider's native governance tools, and continuous cross-cloud CSPM monitoring together provide strong, consistent posture, unlike a set-once configuration with no ongoing monitoring, ignoring native governance constructs, assuming identical responsibility boundaries across providers, disabling monitoring for smaller deployments regardless of sensitivity, or relying solely on manual ad hoc review.