712-50 Question 33
Single answerA global healthcare company is modernizing its IT environment. Its patient records system contains regulated data subject to strict residency and audit requirements, while its analytics team needs rapid access to scalable compute for seasonal research workloads. The board wants to reduce capital expenditure without increasing the organization's risk exposure. As the CISO, which deployment model is the MOST appropriate to recommend?
- A
Adopt a private cloud for all workloads so the organization retains full control over infrastructure, eliminating major cloud security concerns.
- B
Adopt a public cloud for all workloads because major cloud providers assume responsibility for compliance, residency, and security of customer data.
- C
Adopt a hybrid cloud, keeping the regulated patient records system in a tightly governed private environment while using public cloud services for elastic analytics workloads with strong segmentation, encryption, and governance controls.
- D
Adopt a community cloud because organizations in regulated sectors automatically inherit standardized controls and audit evidence from other members of the community.
Show answer and explanation
Correct answer: C
Explanation
The best answer is the hybrid cloud model because it balances control, compliance, scalability, and cost. In this scenario, the patient records system has strict regulatory, residency, and audit requirements, making a private environment more suitable for sensitive workloads that require tailored governance and potentially dedicated infrastructure. At the same time, analytics workloads are seasonal and compute-intensive, making public cloud a strong choice due to elasticity, faster provisioning, and lower capital expenditure.
From a CCISO perspective, the decision should be based on business enablement and risk treatment rather than ideology about any single cloud model. Private cloud benefits include greater control, customization, and potential ease in meeting specialized compliance needs, but it can involve higher cost and greater operational burden. Public cloud benefits include scalability, speed, and cost efficiency, but risks include misconfiguration, concentration risk, data residency concerns, and overreliance on provider-native controls if governance is weak. Hybrid cloud introduces integration and management complexity, but it is often the most practical model for organizations with mixed sensitivity and variable workloads.
Relevant best practices are reflected in the shared responsibility model described by major cloud providers, the NIST definition of cloud computing in SP 800-145, and security guidance from NIST SP 800-53, NIST SP 800-207 for zero trust concepts, and the Cloud Security Alliance Cloud Controls Matrix. These sources consistently emphasize data classification, governance, identity-centric security, encryption, logging, segmentation, and continuous assurance as critical controls across private, public, and hybrid cloud deployments.
- A. Incorrect.
Incorrect. A private cloud can provide greater control, customization, and support for specific residency and audit requirements, which is valuable for highly regulated patient records. However, using private cloud for all workloads would not best address the business need for rapid elastic scaling and reduced capital expenditure. It also does not eliminate major cloud security concerns; the organization still remains responsible for configuration, access control, monitoring, patching, and governance. The misconception is that private cloud inherently removes most cloud risk, when in reality it often shifts more operational responsibility back to the enterprise.
- B. Incorrect.
Incorrect. Public cloud can offer significant scalability, operational efficiency, and lower upfront capital costs, but cloud providers do not assume full responsibility for customer compliance, data residency decisions, or security outcomes. Under the shared responsibility model, customers remain accountable for many controls, including data classification, identity and access management, encryption choices, logging, and secure configuration. This option reflects a common misunderstanding that moving to public cloud transfers all compliance and security obligations to the provider.
- C. Correct.
Correct. A hybrid cloud best aligns with the company's mixed requirements. It allows the organization to retain tighter control over sensitive, regulated patient records in a private environment where residency, auditability, and bespoke controls can be enforced, while leveraging public cloud elasticity for analytics workloads that vary seasonally. This approach supports cost optimization and business agility without forcing a single model onto all workloads. The key security considerations include strong network segmentation, consistent identity and access management, encryption in transit and at rest, centralized logging and monitoring, workload classification, and clear governance over data movement between environments.
- D. Incorrect.
Incorrect. Community cloud may be relevant in some specialized sectors, but it is not the best fit based on the scenario and is not a guarantee of inherited compliance or reusable audit evidence sufficient for the organization's own regulatory obligations. Each organization remains accountable for validating that controls meet its legal, contractual, and risk requirements. This option is appealing because it sounds aligned with regulation, but it overstates the compliance benefit and does not address the need for elastic analytics as effectively as a hybrid approach.