712-50 Question 441
Single answerUnderstand the cost implications of cloud computing and design controls to monitor spending and maintain budgetsA newly appointed CISO is reviewing a cloud-first security program after the organization exceeded its quarterly cloud budget by 28%. The overrun was traced to rapid deployment of security analytics workloads, retention of large volumes of logs in high-cost storage tiers, and multiple development teams launching resources without consistent cost ownership. The board has asked the CISO to implement governance that improves cost predictability without weakening security monitoring. Which action would BEST address the problem while maintaining effective oversight?
- A
Implement mandatory tagging for business owner, environment, and cost center; set budgets and alerts by account/project; and require lifecycle and retention policies that move older logs to lower-cost storage based on business and regulatory requirements.
- B
Purchase the largest available long-term cloud commitment immediately for the security platform to reduce unit costs, then allow teams to continue provisioning resources as needed.
- C
Centralize all cloud security logs indefinitely in the highest-performance storage tier so incident responders can query any dataset instantly without delay.
- D
Block all developer self-service provisioning for cloud resources and require manual CISO approval for every new workload to prevent unplanned spending.
Show answer and explanation
Correct answer: A
Explanation
The best answer is the governance-based approach in Option 1 because it addresses the three root causes in the scenario: lack of cost ownership, insufficient spend monitoring, and uncontrolled growth of expensive security telemetry. From a CCISO perspective, this is not just a technical optimization issue; it is an executive governance problem involving budgeting, accountability, and risk-informed control design. Best practices across major cloud providers and FinOps guidance emphasize resource tagging/labeling for allocation, budgets and cost alerts for proactive oversight, and lifecycle management for storage optimization. Cloud security logging can be one of the largest recurring costs, so CISOs should work with finance, engineering, and compliance teams to define retention periods and storage tiers that meet legal, regulatory, and incident response requirements without keeping all data in premium storage. This approach supports predictability, preserves security visibility, and enables reporting to the board on both risk posture and financial performance.
- A. Correct.
Correct. This option combines financial governance and operational control in a way that aligns with executive accountability. Mandatory tagging improves cost allocation and chargeback/showback, making it possible to identify which business unit or team is driving spend. Budgets and alerts at the account, subscription, or project level enable early detection of anomalies before overruns become material. Log lifecycle and retention policies are especially important because security telemetry often grows rapidly and can become a major cloud cost driver; moving older logs to lower-cost storage while keeping recent data in faster tiers supports both security operations and budget discipline. This approach preserves monitoring capability while applying risk-based retention and storage optimization.
- B. Incorrect.
Incorrect. Committed-use discounts, reserved capacity, or similar long-term purchasing models can reduce costs for stable and predictable workloads, but buying the largest commitment first does not solve the underlying governance issue. If workloads are not well understood, the organization risks overcommitting, locking in spend, and still failing to control sprawl. Allowing teams to continue provisioning without ownership or guardrails perpetuates the same conditions that caused the overrun.
- C. Incorrect.
Incorrect. Keeping all logs indefinitely in the most expensive performance tier is usually not cost-effective and is rarely necessary for all data. Security operations typically require a tiered approach based on use case, incident response windows, compliance requirements, and forensic needs. This option reflects the misconception that maximum performance for all data is inherently more secure. In practice, a defensible retention schedule and storage tiering strategy better balances cost, accessibility, and risk.
- D. Incorrect.
Incorrect. Tightening approval processes may reduce some ad hoc spending, but requiring manual CISO approval for every workload is not scalable and creates operational bottlenecks. It can slow business delivery and encourage shadow IT rather than sustainable governance. Effective cloud cost control generally relies on policy-based guardrails, budget monitoring, tagging, automated enforcement, and accountability at the team level rather than centralized manual approvals for all activity.