SY0-701 exam dumps

SY0-701 practice question 241 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 241

Single answerPlatform diversity: Multi-cloud systems

A company runs customer-facing applications in two different public cloud providers to improve resilience and avoid vendor lock-in. During a security review, the team discovers that administrators use separate local accounts in each cloud console, logging settings are inconsistent between providers, and a former contractor still has access in one environment. The CISO wants to reduce the risk of account compromise and improve visibility across the multi-cloud deployment without redesigning the applications. Which action would BEST address these concerns?

  1. A

    Implement federated identity with centralized IAM and enforce MFA for administrative access across both cloud environments

  2. B

    Place all workloads behind a single CDN so administrative access is routed through one provider

  3. C

    Convert both environments to a hybrid cloud model by moving identity services fully on-premises

  4. D

    Deploy host-based firewalls on all cloud instances and disable each provider's native logging to reduce noise

Show answer and explanation

Correct answer: A

Explanation

The best answer is to implement federated identity with centralized IAM and MFA across both cloud providers. In multi-cloud systems, one of the main security challenges is fragmented administration: separate accounts, inconsistent policies, and uneven offboarding can leave unauthorized access in place. Federation and centralized identity governance help standardize authentication, reduce credential sprawl, and improve deprovisioning. MFA is also a widely recommended control for privileged access.

The scenario also mentions inconsistent logging. Although the best single action focuses on identity because it directly addresses both unauthorized access and account compromise, multi-cloud best practices also include enabling and standardizing audit logging across providers and forwarding logs to a centralized monitoring or SIEM platform. Major cloud security guidance from providers and industry best practices consistently recommends centralized identity, least privilege, MFA for admins, and centralized logging/monitoring for multi-cloud operations.

  • A. Correct.

    Correct. In a multi-cloud environment, centralized identity federation reduces the number of separate privileged accounts that must be managed and helps ensure timely deprovisioning when personnel leave. Enforcing MFA for administrative access directly addresses account compromise risk. Using centralized IAM or federated SSO with each cloud provider also improves governance and consistency across platforms. This is a common best practice for multi-cloud security because it strengthens authentication and simplifies access lifecycle management without requiring application redesign.

  • B. Incorrect.

    Incorrect. A CDN can help with content delivery, DDoS mitigation, and in some architectures traffic distribution, but it does not solve the core issues in the scenario: inconsistent admin account management, weak access governance, and uneven logging across multiple cloud providers. Routing traffic through one provider also does not centralize console authentication or ensure that former contractors are deprovisioned everywhere.

  • C. Incorrect.

    Incorrect. Moving identity services on-premises may be part of some organizations' strategy, but simply converting to hybrid cloud is not the best answer here. The problem is poor identity and access management across multiple clouds, not the absence of on-premises infrastructure. A hybrid model also adds complexity and does not inherently fix logging inconsistency or guarantee better deprovisioning unless federation and centralized access controls are specifically implemented.

  • D. Incorrect.

    Incorrect. Host-based firewalls can improve workload security, but they do not address orphaned administrative accounts or inconsistent cloud-console access controls. Disabling native cloud logging would make visibility worse, not better. In multi-cloud environments, organizations generally want to standardize and aggregate logging rather than turn it off.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam