What Security Control is Essential for Hosting On-Premises Apps in the Cloud?
A security team is setting up a new environment for hosting the organization's on-premises software application as a cloud-based service. Which of the following should the team ensure is in place in order for the organization to follow security best practices?
Community Votes
69% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
It tests your ability to distinguish between foundational infrastructure controls and supplementary security measures, highlighting that secure cloud deployment begins at the hypervisor level before layering data or access protections.
This question evaluates foundational security requirements for migrating on-premises applications to a cloud environment, with community consensus strongly favoring virtualization and resource isolation as the critical architectural baseline.
Candidates frequently choose data encryption because it is a universally recognized best practice, but they miss that encryption cannot mitigate risks like cross-tenant data leakage or VM escape if underlying virtualization and isolation are not properly implemented.
Community Discussion (8 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Core Concept: Hypervisor-Level Security
The correct answer is A. Virtualization and isolation of resources. In cloud computing architectures, especially when hosting applications via IaaS or PaaS, the fundamental security mechanism is the hypervisor. The hypervisor creates logical partitions that isolate virtual machines from one another, ensuring that workloads belonging to different tenants or applications cannot interfere with each other. Without strict resource isolation, even heavily encrypted or authenticated systems remain vulnerable to lateral movement, side-channel attacks, and VM escape exploits.Why Other Options Are Secondary
While B. Network segmentation is vital for limiting blast radius, it operates at the virtual switch or router level and depends on underlying VM isolation. C. Data encryption protects information at rest and in transit, but as noted by community members debating confidentiality versus architecture, encryption does not prevent unauthorized workload execution or hypervisor compromise [2, 3]. D. Strong authentication policies govern user access but do not address the structural integrity of the cloud hosting environment itself. CompTIA Security+ SY0-701 consistently prioritizes the foundational layer of the technology stack; you must secure the platform before securing the data or users running on it.Community Perspectives & Exam Context
The community split between A and C reflects a common real-world debate, but certification exams test standardized architectural principles. Candidates who selected encryption often focus on the what (protecting data) rather than the how (secure hosting infrastructure) [6]. Recognizing that virtualization enables multi-tenancy and resource pooling is key to answering infrastructure-focused cloud questions correctly.Official Reference
Exam Strategy
When faced with cloud infrastructure questions, always identify the foundational layer first. Prioritize controls that enable the technology to operate securely (like hypervisors, virtualization, and physical security) over application-layer controls unless the scenario specifically isolates data handling or identity management.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →