Q5
Single choice
An organization is in the initial phases of cloud adoption. It is not very knowledgeable about cloud security and cloud shared responsibility models.
Which of the following approaches is BEST suited for such an organization to evaluate its cloud security?