Certified In Cybersecurity CC · Free Practice Question Easy
Question 21
Which of the following is the WORST approach to cloud security?
- A Implementing strict access control and monitoring for unauthorized access
- B Regularly updating and patching all cloud systems and applications
- C Using a single cloud provider for all of your organization's data and applications
- D Ignoring security updates and leaving systems vulnerable
Reveal correct answer
Correct answer: D
Explanation
The correct answer: Ignoring security updates and leaving systems vulnerable is the WORST approach to cloud security. Ignoring security updates means not patching the vulnerabilities that the updates are designed to address. This leaves the system open to potential attacks from hackers who are aware of these vulnerabilities and can exploit them to gain unauthorized access to the system, potentially leading to data breaches or other security incidents. The incorrect answers: Regularly updating and patching all cloud systems and applications is a good security practice. Regular updates and patches are necessary to fix security vulnerabilities in systems and applications. Ignoring these updates and patches leaves the systems vulnerable to potential security breaches. Implementing strict access control and monitoring for unauthorized access is a good approach to cloud security. By implementing strict access control, you limit who has access to what data and systems. This reduces the risk of unauthorized access and potential data breaches. Monitoring for unauthorized access helps detect potential security incidents in a timely manner so that they can be addressed before they cause significant damage. Using a single cloud provider could potentially present a single point of failure but it's not necessarily a bad approach to cloud security. In fact, it can simplify management and security monitoring, especially if the cloud provider has robust security controls in place. However, it is important to conduct regular security audits and assessments of the cloud provider to ensure they are maintaining proper security practices.Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
You must be logged in to post a comment.
