Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Cloud SecurityHard
An organization is migrating its legacy applications to a cloud environment. They are concerned about the security implications of 'shadow IT' where employees use unauthorized cloud services for business purposes. Which cloud security best practice primarily helps to gain visibility and control over such unsanctioned cloud usage?
- AImplementing a Cloud Access Security Broker (CASB) solution.
- BConducting regular penetration testing of cloud-hosted applications.
- CEnsuring all cloud resources are tagged appropriately for cost allocation.
- DImplementing strong multi-factor authentication (MFA) for all cloud accounts.
Show answer & explanationAnswer & explanation
Correct answer: A. Implementing a Cloud Access Security Broker (CASB) solution.
Shadow IT is a key challenge that CASBs are designed to address. CASBs can discover and monitor cloud services, sanctioned or unsanctioned, providing visibility into usage, user activity, and data flowing to and from these services, allowing organizations to enforce security policies and mitigate risks associated with shadow IT.
Why the other options are wrong
- B. Penetration testing focuses on the security of specific applications, not the discovery of unauthorized cloud services.
- C. Tagging is for resource management and cost tracking, not for discovering or controlling shadow IT.
- D. MFA enhances authentication security for sanctioned services but doesn't discover or control unsanctioned ones.
Shadow IT Mitigation
Shadow IT refers to the use of IT systems, devices, software, applications, and services without explicit organizational approval. Mitigating it involves gaining visibility and control over all cloud services used by employees.
- CASBs are primary tools for discovering and managing shadow IT.
- Shadow IT poses risks like data leakage, compliance violations, and security vulnerabilities.
- Visibility and policy enforcement are key to mitigation.
Memory trick: CASB is the 'C'loud 'A'ccess 'S'ecurity 'B'ouncer that catches shadow IT.