クラウドの移行後、企業はサードパーティを雇って、クラウドインフラストラクチャの脆弱性を検出するための評価を実施します。次のうち、このプロセスを最もよく表しているのはどれですか?
正解:C
Penetration testing is a simulated attack to assess the security of an organization's cloud-based applications and infrastructure. It is an effective way to proactively identify potential vulnerabilities, risks, and flaws and provide an actionable remediation plan to plug loopholes before hackers exploit them1. Penetration testing is also known as ethical hacking, and it involves evaluating the security of an organization's IT systems, networks, applications, and devices by using hacker tools and techniques2. Penetration testing can be applied to both on-premises and cloud-based environments, making it a more general and broader term2. Cloud penetration testing, on the other hand, is a specialized form of penetration testing that specifically focuses on evaluating the security of cloud-based systems and services. It is tailored to assess the security of cloud computing environments and addresses the unique security challenges presented by cloud service models (IaaS, PaaS, SaaS) and cloud providers23. After a cloud migration, a company hires a third party to conduct an assessment to detect any cloud infrastructure vulnerabilities. This process best describes cloud penetration testing, as it involves simulating real-world attacks and providing insights into the security posture of the cloud environment. Reference: 1: https://www.eccouncil.org/cybersecurity-exchange/penetration-testing/cloud-penetration-testing/ 2: https://www.browserstack.com/guide/cloud-penetration-testing 3: https://cloudsecurityalliance.org/blog/2022/02/12/what-is-cloud-penetration-testing