What Security Control is Essential for Hosting On-Premises Apps in the Cloud?

A security team is setting up a new environment for hosting the organization's on-premises software application as a cloud-based service. Which of the following should the team ensure is in place in order for the organization to follow security best practices?

  1. Virtualization and isolation of resources Source Reference Answer
  2. Network segmentation
  3. Data encryption
  4. Strong authentication policies

Community Votes

A
69%
C
31%

69% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

It tests your ability to distinguish between foundational infrastructure controls and supplementary security measures, highlighting that secure cloud deployment begins at the hypervisor level before layering data or access protections.

This question evaluates foundational security requirements for migrating on-premises applications to a cloud environment, with community consensus strongly favoring virtualization and resource isolation as the critical architectural baseline.

Candidates frequently choose data encryption because it is a universally recognized best practice, but they miss that encryption cannot mitigate risks like cross-tenant data leakage or VM escape if underlying virtualization and isolation are not properly implemented.

Community Discussion (8 comments)

nillie 👍 5 Selected: A
The security team should ensure that all of the following are in place, but the most comprehensive answer that addresses cloud-based services is: A. Virtualization and isolation of resources In a cloud-based environment, virtualization and isolation of resources are critical to maintaining security best practices. Virtualization allows multiple workloads to run on the same physical infrastructure while keeping them isolated from each other, which is a foundational practice in cloud environments to prevent data leakage or unauthorized access between different tenants or applications.
585402e 👍 1 Selected: C
Since it is in the Cloud and theoretically can be compromised at some point, in my opinion, the first thing that needs to be ensured is the confidentiality of the data. Therefore, the data should always be encrypted.
fd91c58 👍 1 Selected: C
The best answer is C. Data encryption. Here's why: Virtualization and isolation of resources: While important for resource management and security, it doesn't directly address the protection of data in transit or at rest. Network segmentation: This helps in limiting the spread of potential breaches but doesn't directly protect the data itself. Data encryption: This is crucial for protecting data both in transit and at rest, ensuring that even if data is intercepted or accessed without authorization, it remains unreadable. Strong authentication policies: These are essential for controlling access to the cloud environment but don't directly protect the data once it is accessed. this makes sense to me data encryption is the basic level of security best practices.
Glacier88 👍 2 Selected: A
Virtualization and isolation of resources: This ensures that each application or tenant within the cloud environment is running in its own isolated virtual environment, preventing unauthorized access or interference from other users. Network segmentation: While network segmentation is a valuable security measure, it's not as directly related to the security of the on-premises software application itself. It's more about protecting the overall network infrastructure. Data encryption: Data encryption is crucial for protecting sensitive data both at rest and in transit, but it's not the primary concern for ensuring a secure cloud-based environment. Strong authentication policies: Strong authentication policies are essential for controlling access to the cloud environment, but they don't address the isolation and protection of resources within that environment.
Yoming 👍 1 Selected: B
Network segmentation would provide a barrier between the hosting software and internal company resources
EfaChux 👍 3 Selected: C
Setting up a private cloud means your data will be traveling over the internet, encryption seems like a best practice to me when compared to virtualization and isolation which could already be in place for the on-premise architecture
Crucible_Bro 👍 4 Selected: A
I'm not overly smart about this type of thing, but I feel like this is one of those trick questions. In order to get any sort of cloud services up you'll need virtualization. The isolation of resources may be part of the security aspect but I am not entirely sure. D is probably a stronger answer but I don't necessarily disagree with A.
a4e15bd 👍 3
D. Strong authentication policies. Ensuring a strong user authentication is crucial to prevent unauthorized access to the cloud environment. This forms the first line of defense in securing the system.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Core Concept: Hypervisor-Level Security

The correct answer is A. Virtualization and isolation of resources. In cloud computing architectures, especially when hosting applications via IaaS or PaaS, the fundamental security mechanism is the hypervisor. The hypervisor creates logical partitions that isolate virtual machines from one another, ensuring that workloads belonging to different tenants or applications cannot interfere with each other. Without strict resource isolation, even heavily encrypted or authenticated systems remain vulnerable to lateral movement, side-channel attacks, and VM escape exploits.

Why Other Options Are Secondary

While B. Network segmentation is vital for limiting blast radius, it operates at the virtual switch or router level and depends on underlying VM isolation. C. Data encryption protects information at rest and in transit, but as noted by community members debating confidentiality versus architecture, encryption does not prevent unauthorized workload execution or hypervisor compromise [2, 3]. D. Strong authentication policies govern user access but do not address the structural integrity of the cloud hosting environment itself. CompTIA Security+ SY0-701 consistently prioritizes the foundational layer of the technology stack; you must secure the platform before securing the data or users running on it.

Community Perspectives & Exam Context

The community split between A and C reflects a common real-world debate, but certification exams test standardized architectural principles. Candidates who selected encryption often focus on the what (protecting data) rather than the how (secure hosting infrastructure) [6]. Recognizing that virtualization enables multi-tenancy and resource pooling is key to answering infrastructure-focused cloud questions correctly.

Official Reference

Exam Strategy

When faced with cloud infrastructure questions, always identify the foundational layer first. Prioritize controls that enable the technology to operate securely (like hypervisors, virtualization, and physical security) over application-layer controls unless the scenario specifically isolates data handling or identity management.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide