200-201 exam dumps

200-201 practice question 17 of 405

Cisco Cybersecurity Associate. Associate level, Cisco. Free question with the correct answer and a full explanation.

200-201 Question 17

Select 3

A company has recently migrated its application workloads to a public cloud provider. The security team is tasked with implementing measures to protect sensitive data and ensure compliance with industry regulations. Which of the following security controls should the team prioritize in this cloud environment?

  1. A

    Enable encryption for data at rest and in transit

  2. B

    Rely solely on the cloud provider's built-in firewalls without additional configuration

  3. C

    Implement identity and access management (IAM) policies with the principle of least privilege

  4. D

    Regularly review and manage cloud resource configurations using a cloud security posture management (CSPM) tool

  5. E

    Disable logging and monitoring to reduce costs in the cloud environment

Show answer and explanation

Correct answers: A, C, D

Explanation

To secure cloud deployments, organizations must adopt measures such as encryption, identity and access management, and continuous monitoring of cloud configurations. These controls help protect sensitive data, limit access to authorized individuals, and ensure compliance with industry standards. Neglecting these practices, such as disabling monitoring or relying solely on default settings, can expose the cloud environment to significant security risks.

  • A. Correct.

    Correct: Encrypting data at rest and in transit ensures the protection of sensitive data from unauthorized access or interception, which is a key cloud security best practice.

  • B. Incorrect.

    Incorrect: While cloud providers offer built-in firewalls, relying solely on them without proper configuration and additional security layers can expose the environment to risks.

  • C. Correct.

    Correct: Implementing IAM policies with the principle of least privilege minimizes the risk of unauthorized access by restricting users and roles to only the permissions they need.

  • D. Correct.

    Correct: A CSPM tool helps identify misconfigurations and ensures that cloud resources comply with security best practices and regulatory requirements.

  • E. Incorrect.

    Incorrect: Disabling logging and monitoring significantly reduces visibility into potential security threats and incidents, which is critical for responding to and mitigating risks in a cloud environment.

Timed practice exam

Take a 200-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam