WGU E025
Cloud and Network Security Models
PERFORMANCE ASSESSMENT - TASK 1
Hybrid Cloud Security Architecture for
MedCore Health Services
Student Name [Insert Name]
Student ID [Insert ID]
Program [Insert Program]
Submission Date August 7, 2026
Organization MedCore Health Services
Academic-use note. This is an original exemplar based on the scenario details supplied. Replace bracketed fields,
validate all assumptions against the current assessment prompt, and adapt the analysis to reflect your own course
learning and sources. Evaluator outcomes cannot be guaranteed.
, Executive Summary
MedCore Health Services operates a headquarters location, five clinics, and a hybrid environment spanning on-premises
systems, Microsoft Azure, and Amazon Web Services (AWS). Its 650-person workforce depends on electronic health
record (EHR), database, collaboration, and cloud services that process electronic protected health information (ePHI).
The current risk profile includes implicit network trust, horizontal reconnaissance, inconsistent access policies between
clouds, data exfiltration, and cloud-resource misconfiguration.
This proposal recommends two distinct but interoperable solutions. Solution 1 is Zero Trust Architecture (ZTA) with
federated identity. It establishes identity-, device-, risk-, and resource-aware access through a policy decision point (PDP)
and policy enforcement points (PEPs). Solution 2 is Cloud Security Posture Management (CSPM) integrated with
next-generation firewalls (NGFWs), data loss prevention (DLP), and centralized logging. CSPM identifies drift and
misconfiguration; NGFW and DLP controls constrain network traffic and ePHI movement.
The estimates are planning-level, not vendor quotations. A mid-range first-year planning envelope is $347,000:
approximately $154,000 for Solution 1, $175,000 for Solution 2, and an $18,000 contingency. Recurring years are
estimated at approximately $198,000 before inflation and changes in cloud consumption. Final procurement requires
competitive quotes, a business associate agreement (BAA) where applicable, architecture validation, and a pilot.
Decision recommendation: approve a phased 12-month program beginning with discovery, identity cleanup, data
classification, and logging; continue with a controlled pilot; then expand enforcement by clinic and workload.
Success will be measured by MFA coverage, privileged-access reduction, blocked lateral movement, cloud
configuration compliance, mean time to remediate, and verified prevention of unauthorized ePHI egress.
Assumptions and Constraints
• MedCore has 650 employees at HQ and five clinics; both Azure and AWS are in scope.
• On-premises EHR and directory services remain operational during migration; no wholesale application replacement is
assumed.
• Representative products are used to demonstrate capability. A competitive selection may substitute functionally
equivalent services.
• TLS inspection will exclude legally or clinically sensitive categories when inspection would create unacceptable privacy,
safety, or application-compatibility risk.
• All cloud vendors handling ePHI must be evaluated for HIPAA eligibility and covered by an appropriate BAA.
Cloud and Network Security Models
PERFORMANCE ASSESSMENT - TASK 1
Hybrid Cloud Security Architecture for
MedCore Health Services
Student Name [Insert Name]
Student ID [Insert ID]
Program [Insert Program]
Submission Date August 7, 2026
Organization MedCore Health Services
Academic-use note. This is an original exemplar based on the scenario details supplied. Replace bracketed fields,
validate all assumptions against the current assessment prompt, and adapt the analysis to reflect your own course
learning and sources. Evaluator outcomes cannot be guaranteed.
, Executive Summary
MedCore Health Services operates a headquarters location, five clinics, and a hybrid environment spanning on-premises
systems, Microsoft Azure, and Amazon Web Services (AWS). Its 650-person workforce depends on electronic health
record (EHR), database, collaboration, and cloud services that process electronic protected health information (ePHI).
The current risk profile includes implicit network trust, horizontal reconnaissance, inconsistent access policies between
clouds, data exfiltration, and cloud-resource misconfiguration.
This proposal recommends two distinct but interoperable solutions. Solution 1 is Zero Trust Architecture (ZTA) with
federated identity. It establishes identity-, device-, risk-, and resource-aware access through a policy decision point (PDP)
and policy enforcement points (PEPs). Solution 2 is Cloud Security Posture Management (CSPM) integrated with
next-generation firewalls (NGFWs), data loss prevention (DLP), and centralized logging. CSPM identifies drift and
misconfiguration; NGFW and DLP controls constrain network traffic and ePHI movement.
The estimates are planning-level, not vendor quotations. A mid-range first-year planning envelope is $347,000:
approximately $154,000 for Solution 1, $175,000 for Solution 2, and an $18,000 contingency. Recurring years are
estimated at approximately $198,000 before inflation and changes in cloud consumption. Final procurement requires
competitive quotes, a business associate agreement (BAA) where applicable, architecture validation, and a pilot.
Decision recommendation: approve a phased 12-month program beginning with discovery, identity cleanup, data
classification, and logging; continue with a controlled pilot; then expand enforcement by clinic and workload.
Success will be measured by MFA coverage, privileged-access reduction, blocked lateral movement, cloud
configuration compliance, mean time to remediate, and verified prevention of unauthorized ePHI egress.
Assumptions and Constraints
• MedCore has 650 employees at HQ and five clinics; both Azure and AWS are in scope.
• On-premises EHR and directory services remain operational during migration; no wholesale application replacement is
assumed.
• Representative products are used to demonstrate capability. A competitive selection may substitute functionally
equivalent services.
• TLS inspection will exclude legally or clinically sensitive categories when inspection would create unacceptable privacy,
safety, or application-compatibility risk.
• All cloud vendors handling ePHI must be evaluated for HIPAA eligibility and covered by an appropriate BAA.