QuestionQ304

Supporting compliance requirements

You work for a company in a regulated industry and are responsible for the Cloud environment’s ongoing security. You must prevent and detect misconfigurations in a particular folder according to specific compliance policies. You must comply with both industry-specific policies and policies internal to your company. What should you do?

  • A Create a Posture file by using custom and predefined SHA or organization policies. Enforce the posture on the folder level.
  • B Create custom organization policies that follow specific business requirements. Enforce the policies on the folder level.
  • C Enable Assured Workloads on the folder level, with the specific control bundle appropriate for your industry’s regulations.
  • D Use Workload Manager with custom Rego policies to continuously scan the environment for misconfigurations on the folder level.
Explanation

Security Command Center security posture management lets an organization define a posture containing custom and predefined Organization Policy and Security Health Analytics controls. A posture can be deployed at the folder level, where it enforces preventative controls and monitors the environment for drift from the defined controls, covering both compliance requirements and internal security policies.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!