問題文
A logistics platform must hold one regulated dataset and several non-regulated apps. The team asks whether one Shield space for everything is a good design. What should the architect say?
選択肢
- Use the shared runtime for the non-regulated apps and no space at all.
- Put everything in one standard space and rely on application-level encryption, and the restriction on data classes applies to the plans rather than to the space, so encrypting the fields in the app satisfies it.
- Separate the workloads: a Shield space imposes its dyno type and restricts operational access for every app inside it, which is unnecessary friction for the non-regulated apps.
- Put everything in one Shield space, because a single space is cheaper than two and the additional restrictions apply only to the applications that actually process regulated data classes rather than to every app that happens to run in the space.